CVE-2010-3747
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 35%
from disclosure to weapon150 days
Published on NVDOct 18
1st PoC+150d
metasploit+28d
exploitation probability
35%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during parsing of a CDDA URI, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and application crash) via a long URI.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16998unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.