CVE-2012-0924
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
08/02/2012
Last modified:
11/04/2025
Description
RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving a VIDOBJ_START_CODE code in a header within a video stream.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.1.609:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.1.633:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:14.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:11.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:11.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:11.0.2.1744:*:*:*:*:*:*:* | ||
| cpe:2.3:a:realnetworks:realplayer:11.0.2.2315:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



