CVE-2007-5081
UnknownEPSS 5.39%
Last modified
CVE-2007-5081 is a vulnerability of currently unknown severity. Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file.. EPSS estimates a 5.39% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Realnetworks | Realone Player | All versions | — |
| Realnetworks | Realone Player | 1.0 | — |
| Realnetworks | Realone Player | 2.0 | — |
| Realnetworks | Realplayer | 8.0 | — |
| Realnetworks | Realplayer | 10.0 | — |
| Realnetworks | Realplayer | 10.1 | 10.0.0.396 |
| Realnetworks | Realplayer | 10.5 | 6.0.12.1040 |
| Realnetworks | Realplayer Enterprise | All versions | — |
References
- http://secunia.com/advisories/27361Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3628Vendor Advisory
- http://secunia.com/advisories/27361Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3628Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5081?
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file.
How severe is CVE-2007-5081?
Severity scoring for CVE-2007-5081 is pending analysis. The EPSS model estimates a 5.39% probability of exploitation in the next 30 days.
How do I fix CVE-2007-5081?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5070Heap-based buffer overflow in the EasyMailMessagePrinter Act…
- CVE-2007-5071Incomplete blacklist vulnerability in upload_img_cgi.php in …
- CVE-2007-5072Multiple cross-site scripting (XSS) vulnerabilities in Simpl…
- CVE-2007-5078Multiple cross-site scripting (XSS) vulnerabilities in eGov …
- CVE-2007-5079Red Hat Enterprise Linux 4 does not properly compile and lin…
- CVE-2007-5080Integer overflow in RealNetworks RealPlayer 10 and 10.5, Rea…
- CVE-2007-5082Multiple stack-based buffer overflows in Computer Associates…
- CVE-2007-5083Multiple integer overflows in Computer Associates (CA) Brigh…
- CVE-2007-5084Multiple SQL injection vulnerabilities in Computer Associate…
- CVE-2007-5085Unspecified vulnerability in the management EJB (MEJB) in Ap…
- CVE-2007-5086Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 1…
- CVE-2007-5087The ATM module in the Linux kernel before 2.4.35.3, when CLI…
Are you affected by CVE-2007-5081?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
