AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2013-2603

HIGH · CVSS 10 EPSS 4.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-01-12 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2013-2603
Severity
HIGH
CVSS
10
EPSS
4.17%

Original Filing — NVD Description

The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the (1) AddTag, (2) Ping, (3) QueuePause, (4) QueueRemove, (5) QueueTop, (6) RemoveTag, (7) TagRemoved, or (8) message method.