Back
CVE-2004-1798
RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| realnetworks | realone_enterprise_desktop | 6.0.11.774 |
| realnetworks | realone_player | 1.0 |
| realnetworks | realone_player | 2.0 |
| realnetworks | realone_player | 6.0.10.505 |
| realnetworks | realone_player | 6.0.11.818 |
| realnetworks | realone_player | 6.0.11.830 |
| realnetworks | realone_player | 6.0.11.841 |
| realnetworks | realone_player | 6.0.11.853 |
| realnetworks | realone_player | 6.0.11.868 |
| realnetworks | realplayer | 8.0 |
GitHub Security Advisory GHSA-qgvq-x96v-cf8x
RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer...
References (12)
- http://secunia.com/advisories/9584 Patch, Vendor Advisory
- http://securitytracker.com/id?1008647 Exploit, Third Party Advisory, VDB Entry
- http://www.osvdb.org/3826 Broken Link, Patch
- http://www.securityfocus.com/archive/1/349086 Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/9378 Exploit, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14168 Third Party Advisory, VDB Entry
- http://secunia.com/advisories/9584 Patch, Vendor Advisory
- http://securitytracker.com/id?1008647 Exploit, Third Party Advisory, VDB Entry
- http://www.osvdb.org/3826 Broken Link, Patch
- http://www.securityfocus.com/archive/1/349086 Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/9378 Exploit, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14168 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
5.1 / 10
EPSS Score
2.19%
Top 19% most likely to be exploited
Threat Score
21.1 / 100
Data Sources
NVD
EPSS
GitHub