Vulnerability Name: | CVE-2010-3001 (CCN-61424) | ||||||||
Assigned: | 2010-08-26 | ||||||||
Published: | 2010-08-26 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | Unspecified vulnerability in an ActiveX control in the Internet Explorer (IE) plugin in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows has unknown impact and attack vectors related to "multiple browser windows." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-3001 Source: CCN Type: SA41096 RealPlayer SP Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 41096 Source: CCN Type: SA41154 RealPlayer Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 41154 Source: CCN Type: SECTRACK ID: 1024370 RealPlayer Bugs Let Remote Users Obtain Files and Execute Arbitrary Code Source: CCN Type: RealNetworks Web Site RealNetworks, Inc. Releases Update to Address Security Vulnerabilities. Source: CONFIRM Type: Vendor Advisory http://service.real.com/realplayer/security/08262010_player/en/ Source: CCN Type: OSVDB ID: 67731 RealPlayer Multiple Products IE Plugin ActiveX Multiple Browser Window Unspecified Issue Source: SECTRACK Type: UNKNOWN 1024370 Source: VUPEN Type: UNKNOWN ADV-2010-2216 Source: XF Type: UNKNOWN Realplayer-activex-unspecified(61424) Source: XF Type: UNKNOWN Realplayer-activex-unspecified(61424) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:7507 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |