Beveiligingsadvies

CVE-2010-4388

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2010-12-14 15:00:00
Laatst bijgewerkt 2024-08-07 03:43:14
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The (1) Upsell.htm, (2) Main.html, and (3) Custsupport.html components in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allow remote attackers to inject code into the RealOneActiveXObject process, and consequently bypass intended Local Machine Zone restrictions and load arbitrary ActiveX controls, via unspecified vectors.