CVE-2008-1309
Last modified
CVE-2008-1309 is a vulnerability of currently unknown severity. The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.. EPSS estimates a 45.95% chance of exploitation in the next 30 days.
Description
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Realnetworks | Realplayer | All versions |
| Realnetworks | Realplayer | 10.0 |
| Realnetworks | Realplayer | 10.5 |
| Realnetworks | Realplayer | 11 |
References
- http://secunia.com/advisories/29315Vendor Advisory
- http://www.kb.cert.org/vuls/id/831457US Government Resource
- http://www.vupen.com/english/advisories/2008/0842Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2194/referencesVendor Advisory
- http://secunia.com/advisories/29315Vendor Advisory
- http://www.kb.cert.org/vuls/id/831457US Government Resource
- http://www.vupen.com/english/advisories/2008/0842Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2194/referencesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1309?
How severe is CVE-2008-1309?
How do I fix CVE-2008-1309?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-1303The Perforce service (p4s.exe) in Perforce Server 2007.3/143…
- CVE-2008-1304Multiple cross-site scripting (XSS) vulnerabilities in WordP…
- CVE-2008-1305SQL injection vulnerability in filebase.php in the Filebase …
- CVE-2008-1306Multiple cross-site scripting (XSS) vulnerabilities in Savvy…
- CVE-2008-1307Heap-based buffer overflow in the KUpdateObj2 Class ActiveX …
- CVE-2008-1308SQL injection vulnerability in the Sudirman Angriawan NukeC3…
- CVE-2008-1310Directory traversal vulnerability in the TFTP server in Pack…
- CVE-2008-1311The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.…
- CVE-2008-1312Unspecified vulnerability in the TFTP server in PacketTrap N…
- CVE-2008-1313Multiple SQL injection vulnerabilities in index.php in Bloo …
- CVE-2008-1314SQL injection vulnerability in the Johannes Hass gaestebuch …
- CVE-2008-1315SQL injection vulnerability in the ZClassifieds module for P…
Are you affected by CVE-2008-1309?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
