Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-4388

EPSS 0.39% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-4388

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The (1) Upsell.htm, (2) Main.html, and (3) Custsupport.html components in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allow remote attackers to inject code into the RealOneActiveXObject process, and consequently bypass intended Local Machine Zone restrictions and load arbitrary ActiveX controls, via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
RealNetworks RealPlayer RealOneActiveXObject进程输入验证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
RealPlayer是Real Networks公司发布和维护的一个软件包,可以用来播放Real Media格式编码的多媒体文件。 RealNetworks RealPlayer 11.0至11.1版本,RealPlayer SP 1.0至1.1.5版本,RealPlayer Enterprise 2.1.2及2.1.3版本中的(1)Upsell.htm,(2)Main.html,以及(3)Custsupport.html组件中存在输入验证漏洞。远程攻击者可以借助未明向量向RealOneActiveXOb
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-4388

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-4388

Please Login to view more intelligence information

Same Patch Batch · n/a · 2010-12-14 · 29 CVEs total

CVE-2010-4382RealNetworks RealPlayer RealMedia文件多个堆缓冲区溢出漏洞
CVE-2010-4397RealNetworks RealPlayer pnen3260.dll模块整数溢出漏洞
CVE-2010-4396RealNetworks RealPlayer HandleAction方法跨域脚本攻击漏洞
CVE-2010-4395RealNetworks RealPlayer堆缓冲区溢出漏洞
CVE-2010-4394RealNetworks RealPlayer HTTP请求堆缓冲区溢出漏洞
CVE-2010-4392RealNetworks RealPlayer ImageMap数据堆缓冲区溢出漏洞
CVE-2010-4391RealNetworks RealPlayer RMX文件堆缓冲区溢出漏洞
CVE-2010-4390RealNetworks RealPlayer IVR文件堆缓冲区溢出漏洞
CVE-2010-4389RealNetworks RealPlayer cook编解码器堆缓冲区溢出漏洞
CVE-2010-4387RealNetworks RealPlayer RealAudio编解码器缓冲区溢出漏洞
CVE-2010-4386RealNetworks RealPlayer RealMedia视频文件缓冲区溢出漏洞
CVE-2010-4385RealNetworks RealPlayer SIPR流整数溢出漏洞
CVE-2010-4384RealNetworks RealPlayer MDPR数组索引错误漏洞
CVE-2010-4383RealNetworks RealPlayer RA5文件堆缓冲区溢出漏洞
CVE-2010-0121RealNetworks RealPlayer cook编解码器初始化错误漏洞
CVE-2010-4381RealNetworks RealPlayer AAC文件堆缓冲区溢出漏洞
CVE-2010-4380RealNetworks RealPlayer SOUND文件堆缓冲区溢出漏洞
CVE-2010-4379RealNetworks RealPlayer SIPR文件堆缓冲区溢出漏洞
CVE-2010-4378RealNetworks RealPlayer drv2.dll模块缓冲区溢出漏洞
CVE-2010-4377RealNetworks RealPlayer 实时音频文件堆缓冲区溢出漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-4388

No comments yet


Leave a comment