Back

CVE-2005-2936

Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file.

Published: Nov 18, 2005 Modified: Jun 16, 2026
CWE-264

CVSS Metrics

Affected Products (6)

Vendor Product Version
realnetworks realone_player 1.0
realnetworks realone_player 2.0
realnetworks realplayer 8.0
realnetworks realplayer 10.0
realnetworks realplayer 10.5_6.0.12.1040
realnetworks realplayer 10.5_6.0.12.1348

GitHub Security Advisory GHSA-cp96-2fvh-r4w7

Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 3.34%

Top 12% most likely to be exploited

Threat Score 29.8 / 100

Data Sources

NVD EPSS GitHub