CVE-2012-2408: Realnetworks Realplayer

Medium severity, CVSS 6.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.

Affected products

  • Realnetworks Realplayer: up to and including 15.0.5.109; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; version 4 only; version 5 only; …
  • Realnetworks Realplayer SP: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.5 only; version 1.1 only; version 1.1.1 only; …

Published 2012-09-12. Last modified 2026-06-16.