Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-0190

EPSS 3.11% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-0190

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
RealNetworks Realplayer远程任意文件删除漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
RealPlayer/RealOne是一款由RealNetworks公司提供的用于播放在线音频和视频的软件。 RealPlayer/RealOne存在一个安全问题,远程攻击者可以利用这个漏洞通过使用用户交互的网页诱使用户处理,删除用户系统上的文件。 RealPlayer/RealOne支持私有包递送文件类型,命令为Real Metadata Packages,这些文件包含HTML类型语言,包含各种包和RealPlayer扩展的信息和资源URL。 其中一个支持的包含在RMP文件类型中的标记是<FILENAM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-0190

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-0190

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-02-06 · 65 CVEs total

CVE-2005-0196Cisco IOS畸形BGP包远程拒绝服务漏洞
CVE-2005-0221Gallery login.php 跨站脚本攻击漏洞
CVE-2005-0224HP Virtualvault 拒绝服务漏洞
CVE-2005-0223Tru64 UNIX漏洞
CVE-2005-0222Gallery信息泄露漏洞
CVE-2005-0211Squid Proxy WCCP recvfrom()远程缓冲区溢出漏洞
CVE-2005-0200TikiWiki未明安全漏洞
CVE-2005-0199ngIRCd远程缓冲区溢出漏洞
CVE-2005-0198University Of Washington IMAP Server CRAM-MD5远程身份验证绕过漏洞
CVE-2005-0197Cisco IOS畸形MPLS包远程拒绝服务漏洞
CVE-2005-0212Amp II 3D远程拒绝服务漏洞
CVE-2005-0195Cisco IOS远程拒绝服务漏洞
CVE-2005-0194Squid 权限管理和访问控制漏洞
CVE-2005-0193Apple MacOS iSync mRouter 缓存区溢出漏洞
CVE-2005-0192RealPlayer解析Skin文件名目录遍历漏洞
CVE-2005-0191RealNetwork RealPlayer RealMetadataPackage 缓冲区溢出漏洞
CVE-2005-0189RealNetworks Realplayer 'ShowPreferences'远程缓冲区溢出漏洞
CVE-2005-0188AtHoc Toolbar远程缓冲区及格式串漏洞
CVE-2005-0187AtHoc Toolbar远程缓冲区及格式串漏洞
CVE-2005-0186Cisco IOS SCCP 拒绝服务漏洞

Showing top 20 of 65 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2005-0190

No comments yet


Leave a comment