CVE-2013-6877: Realnetworks Realplayer

High severity, CVSS 9.3. EPSS: 11.3% chance of exploitation in the next 30 days.

Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a long string in the TRACKID element of an RMP file, a different vulnerability than CVE-2013-7260.

Affected products

  • Realnetworks Realplayer: version 16.0.2.32 only; version 16.0.3.51 only

Published 2013-12-19. Last modified 2026-06-17.