CVE-2008-1309
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 46%
- Percentile among all scored CVEs: 99
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Metasploit module (reliable, widely available exploit) · RealPlayer rmoc3260.dll ActiveX Control Heap Corruption
- Published on Exploit-DB · RealPlayer - 'rmoc3260.dll' ActiveX Control Heap Corruption (Metasploit) (6/15/2010)
- Published on Exploit-DB · Real Player - 'rmoc3260.dll' ActiveX Control Remote Code Execution (4/1/2008)
Affected technologies (1)
CWEs
- CWE-399
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html
- http://secunia.com/advisories/29315
- http://service.real.com/realplayer/security/07252008_player/en/
- http://www.kb.cert.org/vuls/id/831457
- http://www.securityfocus.com/archive/1/494779/100/0/threaded
- http://www.securityfocus.com/bid/28157
- http://www.securitytracker.com/id?1019576
- http://www.securitytracker.com/id?1020563
- http://www.vupen.com/english/advisories/2008/0842
- http://www.vupen.com/english/advisories/2008/2194/references
- http://www.zerodayinitiative.com/advisories/ZDI-08-047/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41087
- https://www.exploit-db.com/exploits/5332
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html
- http://secunia.com/advisories/29315
- http://service.real.com/realplayer/security/07252008_player/en/
- http://www.kb.cert.org/vuls/id/831457
- http://www.securityfocus.com/archive/1/494779/100/0/threaded
- http://www.securityfocus.com/bid/28157
- http://www.securitytracker.com/id?1019576
- http://www.securitytracker.com/id?1020563
- http://www.vupen.com/english/advisories/2008/0842
- http://www.vupen.com/english/advisories/2008/2194/references
- http://www.zerodayinitiative.com/advisories/ZDI-08-047/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41087
- https://www.exploit-db.com/exploits/5332
Raw JSON (NVD)
Show
{
"id": "CVE-2008-1309",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-03-12T17:44:00.000",
"references": [
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29315",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://service.real.com/realplayer/security/07252008_player/en/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/831457",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/494779/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28157",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019576",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1020563",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0842",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2194/references",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-08-047/",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41087",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5332",
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2008-March/060659.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29315",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://service.real.com/realplayer/security/07252008_player/en/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/831457",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/494779/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/28157",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019576",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020563",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0842",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2194/references",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-08-047/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41087",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/5332",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory."
},
{
"lang": "es",
"value": "El control de ActiveX RealAudioObjects.RealAudio en rmoc3260.dll en RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 en versiones anteriores a build 6.0.12.1675 y RealPlayer 11 en versiones anteriores a 11.0.3 build 6.0.14.806 no gestiona adecuadamente la memoria para la propiedad (1) Console o (2) Controls, lo que permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (caída del navegador) a través de una serie de asignaciones de valores de cadena larga, lo que desencadena una sobrescritura de la memoria dinámica liberada."
}
],
"lastModified": "2026-06-16T22:51:28.270",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:*:*:enterprise:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19BC5A59-BCBD-4859-8329-B4974D43DB90"
},
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD49D16C-B0AC-4228-9984-010661596232"
},
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "348F3214-E5C2-4D39-916F-1B0263D13F40"
},
{
"criteria": "cpe:2.3:a:realnetworks:realplayer:11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72A94395-4F1A-4310-85A8-F46A76EE3A12"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Not vulnerable. This issue did not affect versions of RealPlayer as shipped with Red Hat Enterprise Linux 3 Extras, 4 Extras, or 5 Supplementary.",
"lastModified": "2008-03-18T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}