← Back

Realplayer

realplayer

Vendor: Realnetworks • 170 CVEs

CVEs (170)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted RTSP SETUP request.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the RV20 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The RV10 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via a crafted sample height.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the ATRC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Array index error in the RV30 codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed AAC file.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted QCELP stream.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The AAC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The RealVideo renderer in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vec...Show more
The RealVideo renderer in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.Show less
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the RealVideo renderer in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors.
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Oct 4, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 al...Show more
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document, a different vulnerability than CVE-2011-2947.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5, when an Embedded RealPlayer is used, allo...Show more
Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5, when an Embedded RealPlayer is used, allows remote attackers to execute arbitrary code via vectors related to a modal dialog.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in the AutoUpdate feature in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5, when an Embedded RealPlayer is used, allows remote attack...Show more
Use-after-free vulnerability in the AutoUpdate feature in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5, when an Embedded RealPlayer is used, allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
An unspecified ActiveX control in the browser plugin in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote atta...Show more
An unspecified ActiveX control in the browser plugin in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via unknown vectors, related to an out-of-bounds condition.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitra...Show more
Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via vectors related to a dialog box.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.0.0.1569 allows remote attackers to execute arbitrary code via a crafted raw_...Show more
Buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.0.0.1569 allows remote attackers to execute arbitrary code via a crafted raw_data_frame field in an AAC file.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted QCP...Show more
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted QCP file.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary...Show more
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via crafted ID3v2 tags in an MP3 file.Show less
1Realnetworks
2Realplayer
Realplayer Sp
Apr 29, 2026
Aug 18, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, RealPlayer Enterprise 2.0 through 2.1.5, and Mac RealPlayer 12.0.0.1569 do not properly handle DEFINEFONT fields in SW...Show more
RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, RealPlayer Enterprise 2.0 through 2.1.5, and Mac RealPlayer 12.0.0.1569 do not properly handle DEFINEFONT fields in SWF files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted file.Show less