CVE-2007-5601
Status: ModifiedHigh (9.3)—💥 Exploit
Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 42%
- Percentile among all scored CVEs: 99
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Metasploit module (reliable, widely available exploit) · RealPlayer ierpplug.dll ActiveX Control Playlist Name Buffer Overflow
- Published on Exploit-DB · RealPlayer - 'ierpplug.dll' ActiveX Control Playlist Name Buffer Overflow (Metasploit) (5/9/2010)
- Published on Exploit-DB · RealPlayer 10.0/10.5/11 - 'ierpplug.dll' ActiveX Control Import Playlist Name Stack Buffer Overflow (10/18/2007)
Affected technologies (1)
CWEs
- CWE-119
References
- http://secunia.com/advisories/27248
- http://service.real.com/realplayer/security/191007_player/en/
- http://www.infosecblog.org/2007/10/nasa-bans-ie.html
- http://www.kb.cert.org/vuls/id/871673
- http://www.securityfocus.com/bid/26130
- http://www.securitytracker.com/id?1018843
- http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html
- http://www.us-cert.gov/cas/techalerts/TA07-297A.html
- http://www.vupen.com/english/advisories/2007/3548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37280
- http://secunia.com/advisories/27248
- http://service.real.com/realplayer/security/191007_player/en/
- http://www.infosecblog.org/2007/10/nasa-bans-ie.html
- http://www.kb.cert.org/vuls/id/871673
- http://www.securityfocus.com/bid/26130
- http://www.securitytracker.com/id?1018843
- http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html
- http://www.us-cert.gov/cas/techalerts/TA07-297A.html
- http://www.vupen.com/english/advisories/2007/3548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37280
Raw JSON (NVD)
Show
{
"id": "CVE-2007-5601",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-10-20T20:17:00.000",
"references": [
{
"url": "http://secunia.com/advisories/27248",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://service.real.com/realplayer/security/191007_player/en/",
"source": "cret@cert.org"
},
{
"url": "http://www.infosecblog.org/2007/10/nasa-bans-ie.html",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/871673",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/26130",
"source": "cret@cert.org"
},
{
"url": "http://www.securitytracker.com/id?1018843",
"source": "cret@cert.org"
},
{
"url": "http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html",
"source": "cret@cert.org"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA07-297A.html",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3548",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37280",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/27248",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://service.real.com/realplayer/security/191007_player/en/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.infosecblog.org/2007/10/nasa-bans-ie.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/871673",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26130",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018843",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA07-297A.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3548",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37280",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll."
},
{
"lang": "es",
"value": "Un desbordamiento de búfer en la región stack de la memoria en el Database Component en la biblioteca MPAMedia.dll en RealNetworks RealPlayer versiones 10.5 y 11 beta, y anteriores, incluyendo versión 10, RealOne Player y RealOne Player versión 2, permite a atacantes remotos ejecutar código arbitrario por medio de ciertos nombres de lista de reproducción, como es demostrado por medio del método import en el control ActiveX IERPCtl en la biblioteca ierpplug.dl."
}
],
"lastModified": "2026-06-16T22:46:28.583",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD49D16C-B0AC-4228-9984-010661596232"
},
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "348F3214-E5C2-4D39-916F-1B0263D13F40"
},
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:11_beta:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64C3CD7C-9CD8-4BC3-9ECE-CE39FB02E602"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Not vulnerable. This issue did not affect versions of RealPlayer as shipped with Red Hat Enterprise Linux 3 and 4 Extras or with Red Hat Enterprise Linux 5 Supplementary.",
"lastModified": "2007-10-23T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cret@cert.org"
}