CVE-2008-5911
Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.
Published:Jan 20, 2009
Last Modified:Apr 23, 2026
EPS:Jan 20, 2009
EPSS Score:0.16434
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Realnetworks
Product
Helix Server
Realnetworks
Helix Server
Vendor
Realnetworks
Product
Helix Server Mobile
Realnetworks
Helix Server Mobile
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
