Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-0416
Description:Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-0416
38450
http://secunia.com/advisories/38450
RHSA-2010:0094
http://www.redhat.com/support/errata/RHSA-2010-0094.html
[common-cvs] 20070703 util hxurl.cpp,1.24.4.1,1.24.4.1.4.1
http://lists.helixcommunity.org/pipermail/common-cvs/2007-July/014956.html
https://bugzilla.redhat.com/show_bug.cgi?id=561856
https://bugzilla.redhat.com/show_bug.cgi?id=561856
https://helixcommunity.org/viewcvs/common/util/hxurl.cpp?view=log#rev1.24.4.1.4.1
https://helixcommunity.org/viewcvs/common/util/hxurl.cpp?view=log#rev1.24.4.1.4.1
oval:org.mitre.oval:def:10847
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10847




© 1998-2025 E-Soft Inc. All rights reserved.