CVE-2016-9018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
28/10/2016
Last modified:
12/04/2025

Description

Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:realnetworks:realplayer:18.1.5.705:*:*:*:*:*:*:*