RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.
References
Link | Resource |
---|---|
http://secunia.com/advisories/11395 | Broken Link Vendor Advisory |
http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities | Broken Link Exploit Patch Vendor Advisory |
http://www.securityfocus.com/bid/10157 | Broken Link Exploit Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15880 | Third Party Advisory VDB Entry |
http://secunia.com/advisories/11395 | Broken Link Vendor Advisory |
http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities | Broken Link Exploit Patch Vendor Advisory |
http://www.securityfocus.com/bid/10157 | Broken Link Exploit Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15880 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/11395 - Broken Link, Vendor Advisory | |
References | () http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities - Broken Link, Exploit, Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/10157 - Broken Link, Exploit, Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/15880 - Third Party Advisory, VDB Entry |
15 Feb 2024, 21:42
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-476 | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/15880 - Third Party Advisory, VDB Entry | |
References | (SECUNIA) http://secunia.com/advisories/11395 - Broken Link, Vendor Advisory | |
References | (BID) http://www.securityfocus.com/bid/10157 - Broken Link, Exploit, Third Party Advisory, VDB Entry | |
References | (IDEFENSE) http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities - Broken Link, Exploit, Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 7.8
v3 : 7.5 |
Information
Published : 2004-06-01 04:00
Updated : 2024-11-20 23:48
NVD link : CVE-2004-0389
Mitre link : CVE-2004-0389
CVE.ORG link : CVE-2004-0389
JSON object : View
Products Affected
realnetworks
- helix_universal_server
CWE
CWE-476
NULL Pointer Dereference