rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/73018
http://www.securityfocus.com/bid/51883
http://service.real.com/realplayer/security/02062012_player/en/