CVE-2006-1370
Last modified
CVE-2006-1370 is a vulnerability of currently unknown severity. Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.. EPSS estimates a 2.95% chance of exploitation in the next 30 days.
Description
Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Realnetworks | Realone Player | 1.0 |
| Realnetworks | Realone Player | 2.0 |
| Realnetworks | Realplayer | All versions |
| Realnetworks | Realplayer | 8.0 |
| Realnetworks | Realplayer | 10.0 |
| Realnetworks | Realplayer | 10.5_6.0.12.1040 |
| Realnetworks | Realplayer | 10.5_6.0.12.1053 |
| Realnetworks | Realplayer | 10.5_6.0.12.1056 |
| Realnetworks | Realplayer | 10.5_6.0.12.1059 |
| Realnetworks | Realplayer | 10.5_6.0.12.1069 |
| Realnetworks | Realplayer | 10.5_6.0.12.1235 |
| Realnetworks | Realplayer | 10.5_6.0.12.1348 |
References
- http://secunia.com/advisories/19358Vendor Advisory
- http://www.kb.cert.org/vuls/id/451556US Government Resource
- http://secunia.com/advisories/19358Vendor Advisory
- http://www.kb.cert.org/vuls/id/451556US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1370?
How severe is CVE-2006-1370?
How do I fix CVE-2006-1370?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-1364Microsoft w3wp (aka w3wp.exe) does not properly handle when …7.5
- CVE-2006-1365The Motorola PEBL U6, the Motorola V600, and possibly the Mo…
- CVE-2006-1366Buffer overflow in the Motorola PEBL U6 08.83.76R, and possi…
- CVE-2006-1367The Motorola PEBL U6 08.83.76R, the Motorola V600, and possi…
- CVE-2006-1368Buffer overflow in the USB Gadget RNDIS implementation in th…
- CVE-2006-1369Cross-site scripting (XSS) vulnerability in Invision Power B…
- CVE-2006-1371Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earli…
- CVE-2006-1372Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 a…
- CVE-2006-1373Cross-site scripting (XSS) vulnerability in status_image.php…
- CVE-2006-1374SQL injection vulnerability in viewStatement.php in AdMan 1.…
- CVE-2006-1375AdMan 1.0.20051221 and earlier allows remote attackers to ob…
- CVE-2006-1376The installation of Debian GNU/Linux 3.1r1 from the network …
Are you affected by CVE-2006-1370?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
