CVE-2002-1643
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 74%
from disclosure to weapon0 days
Published on NVDMar 28
1st PoCDec 20
metasploitDec 20
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/16286unverifiedexploitdbwww.exploit-db.com/exploits/9937unverifiedexploitdbwww.exploit-db.com/exploits/23unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://exchange.xforce.ibmcloud.com/vulnerabilities/10915https://exchange.xforce.ibmcloud.com/vulnerabilities/10916https://exchange.xforce.ibmcloud.com/vulnerabilities/10917http://www.kb.cert.org/vuls/id/974689http://www.nextgenss.com/advisories/realhelix.txthttp://www.securityfocus.com/archive/1/304203http://www.securityfocus.com/bid/6454http://www.securityfocus.com/bid/6456http://www.securityfocus.com/bid/6458http://www.service.real.com/help/faq/security/bufferoverrun12192002.html