An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.Referenceshttp://www.securityfocus.com/bid/21802https://exchange.xforce.ibmcloud.com/vulnerabilities/31141http://downloads.securityfocus.com/vulnerabilities/exploits/21802.htmlhttps://www.exploit-db.com/exploits/3030