CVE-2014-3113: Realnetworks Realplayer

High severity, CVSS 9.3. EPSS: 5.2% chance of exploitation in the next 30 days.

Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.

Affected products

  • Realnetworks Realplayer: up to and including 17.0.8.22; version 17.0.4.60 only

Published 2014-07-07. Last modified 2026-06-17.