RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted video dimensions in an MP4 file.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-4203
http://service.real.com/realplayer/security/11182011_player/en/