CVE Database
/

CVE-2010-4388

Back to search

CVE-2010-4388

Published: Dec 14, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

The (1) Upsell.htm, (2) Main.html, and (3) Custsupport.html components in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allow remote attackers to inject code into the RealOneActiveXObject process, and consequently bypass intended Local Machine Zone restrictions and load arbitrary ActiveX controls, via unspecified vectors.

VendorProductVersions

n/a

n/a

affected
n/a

References

69859
vdb-entry
x_refsource_OSVDB
69858
vdb-entry
x_refsource_OSVDB
1024861
vdb-entry
x_refsource_SECTRACK
69857
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now