Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-0376

EPSS 20.22% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-0376

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Heap-based buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a modified field that controls an unspecified structure length and triggers heap corruption, related to use of RealPlayer through a Windows Explorer plugin.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
RealNetworks RealPlayer IVR文件解析多个代码执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
RealNetworks RealNetworks RealPlayer是美国RealNetworks公司开发的一套媒体播放器产品。该产品提供下载/转换视频(在网页中)、编辑视频、管理媒体文件等功能。 RealNetworks RealPlayer的IVR文件处理例程中存在基于堆的缓冲区溢出漏洞。如果攻击者更改了IVR文件中用于确定结构长度的字段的话,就可以触发堆溢出;如果在IVR文件中设置了超长的文件名长度值的话,就会向任意内存地址写入一个空字节。该漏洞存在于一个可用作Windows资源管理器shell
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-0376

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-0376

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-02-08 · 14 CVEs total

CVE-2009-0210AREVA e-terrahabitat 多个安全漏洞
CVE-2009-0211AREVA e-terrahabitat WebFGServer应用程序拒绝服务漏洞
CVE-2009-0212AREVA e-terrahabitat WebFGServe应用程序拒绝服务漏洞
CVE-2009-0213AREVA e-terrahabitat NETIO应用程序拒绝服务漏洞
CVE-2009-0214AREVA e-terrahabitat WebFGServer应用程序拒绝服务漏洞
CVE-2009-0478Squid Web Proxy Cache HTTP Version Number Parsing 拒绝服务漏洞
CVE-2008-4559HP OpenView网络节点管理器输入验证错误漏洞
CVE-2008-4560HP OpenView网络节点管理器多个信息泄露漏洞
CVE-2008-4562HP OpenView网络节点管理器ovlaunch缓冲区错误漏洞
CVE-2009-0206HP-UX NFS 未明本地拒绝服务漏洞
CVE-2009-0375RealNetworks RealPlayer IVR文件解析多个代码执行漏洞
CVE-2009-0476MultiMedia Soft多个组件AdjMmsEng.dll PLS文件处理栈溢出漏洞
CVE-2009-0477Sun OpenSolaris Process File System 本地代码执行漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-0376

No comments yet


Leave a comment