Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*", "matchCriteriaId": "A8985B3B-BCC9-431D-9788-0C1949DF46E3", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:*", "matchCriteriaId": "D03738C3-D659-488D-B285-64A496C0F1FB", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "E70D263C-820C-4399-9215-D69082024287", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "6F6486B4-AEDB-428C-9F10-A494681577D4", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "D825DDF3-5D19-403E-8990-58521314E99B", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:14.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "27B4A01C-B07A-4879-926B-8C5F272F5662", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:14.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "F9EA3EBA-DDB3-4C2E-BC78-9225E4D65C6E", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:14.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "9FEB9795-829C-4F2A-A796-EF0025E993F4", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "8BFD9C4F-E93B-4BCE-A5E2-A20945EB8534", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "5BBEBAA2-4892-4F9E-8C0E-94CA90DCD28D", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "53D7AE43-A3AC-4B38-B0A3-E6F02834224F", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "59FEDCDF-9FBF-4D08-A50F-FF92763DFC21", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.1:*:*:*:*:*:*:*", "matchCriteriaId": "54A11B3A-547C-4F2F-A58E-DE06DBBE8115", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "C7243D80-913D-405C-9988-B8473DB1A5DC", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "D4C6D399-FF31-441D-A363-BD53CFE5569A", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "9818A6FB-2CF5-4236-8EFE-95458D603CC1", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.1.4:*:*:*:*:*:*:*", "matchCriteriaId": "73CC0582-D889-4907-A32E-218AC2B0591F", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer_sp:1.1.5:*:*:*:*:*:*:*", "matchCriteriaId": "2B5DD6CF-CCC7-40DD-A6CA-B9BBC339998F", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:realnetworks:realplayer:2.0:*:enterprise:*:*:*:*:*", "matchCriteriaId": "58276A5F-A6A2-470F-9739-878B7785C3E7", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:2.1.2:*:enterprise:*:*:*:*:*", "matchCriteriaId": "1E2BC096-43B6-4696-8467-CC3D0163EFF5", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:2.1.3:*:enterprise:*:*:*:*:*", "matchCriteriaId": "3A29D4B9-DD00-43F6-ACEA-B830FDFC1E5C", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:2.1.4:*:enterprise:*:*:*:*:*", "matchCriteriaId": "320D3DA6-DD8C-4423-84E5-55906D47BD6B", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:2.1.5:*:enterprise:*:*:*:*:*", "matchCriteriaId": "CBE40E84-0053-4173-A60F-53979881E41F", "vulnerable": true}, {"criteria": "cpe:2.3:a:realnetworks:realplayer:12.0.0.1569:*:mac_os:*:*:*:*:*", "matchCriteriaId": "5A1083BF-25B9-44A6-B376-CC39EEACF493", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, RealPlayer Enterprise 2.0 through 2.1.5, and Mac RealPlayer 12.0.0.1569 do not properly handle DEFINEFONT fields in SWF files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted file."}, {"lang": "es", "value": "RealNetworks RealPlayer v11.0 a v11.1 y v14.0.0 a v14.0.5, RealPlayer SP v1.0 a v1.1.5, RealPlayer Enterprise v2.0 a v2.1.5 y Mac RealPlayer v12.0.0.1569 no gestionan adecuadamente los campos DEFINEFONT en los archivos SWF, lo que permite ejecutar c\u00f3digo arbitrario o causar una denegaci\u00f3n de servicio (corrupci\u00f3n de memoria heap) a atacantes remotos a trav\u00e9s de un archivo debidamente modificado."}], "id": "CVE-2011-2948", "lastModified": "2025-04-11T00:51:21.963", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 9.3, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}]}, "published": "2011-08-18T23:55:00.913", "references": [{"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://service.real.com/realplayer/security/08162011_player/en/"}, {"source": "cve@mitre.org", "url": "http://www.securitytracker.com/id?1025943"}, {"source": "cve@mitre.org", "url": "http://zerodayinitiative.com/advisories/ZDI-11-268/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://service.real.com/realplayer/security/08162011_player/en/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id?1025943"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://zerodayinitiative.com/advisories/ZDI-11-268/"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-119"}], "source": "nvd@nist.gov", "type": "Primary"}]}