CVE-2016-9018
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
- Affected products
- Realplayer
- Realnetworks Realplayer
- = 18.1.5.705
- Fix
- Available
- CVSS 3.0
- 5.5 MEDIUM
- EPSS
- 4.8% (91th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2016-10-28
CVE-2016-9018 at NVD
1 known exploit for CVE-2016-9018
Proof-of-concept code and exploit modules indexed by Sploitus