RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file.
http://www.securityfocus.com/bid/61990
http://service.real.com/realplayer/security/08232013_player/en/