« Volver al listado

CVE-2012-0942

Estado: ModificadaAlta (7.5)—

Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-0942",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-04-17T04:26:07.667",
  "references": [
    {
      "url": "http://helixproducts.real.com/docs/security/SecurityUpdate04022012HS.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/52929",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1026898",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://helixproducts.real.com/docs/security/SecurityUpdate04022012HS.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/52929",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1026898",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en rn5auth.dll en RealNetworks Helix Server y Helix Mobile Server v14.x anteriores a v14.3.x permite a atacantes remotos ejecutar código a través de credenciales de autenticación manipuladas."
    }
  ],
  "lastModified": "2026-06-16T23:38:33.033",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server:14.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCA41FC7-3705-4E40-805C-8A82DDF0188F"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server:14.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E39B1E7-515E-49B9-BB32-18D964F723AF"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server:14.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3778BD8-B48F-44A8-98C0-722A3D698E77"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_server:14.2.0.212:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61DA236F-4214-4014-B401-CA4E18337A40"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_mobile_server:14.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD06FC5A-80AB-4A49-8F49-421D871775C1"
            },
            {
              "criteria": "cpe:2.3:a:realnetworks:helix_mobile_server:14.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EA0E7AC-DEB4-4B41-9AEB-0752447CA6A0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}