http://bugs.winehq.org/show_bug.cgi?id=9546
--- Comment #1 from Dmitry Timoshkov dmitry@codeweavers.com 2007-09-01 22:58:40 --- Looks like a missing NULL check. Since an additional information is missing I looked in the code and found that only EM_REPLACESEL doesn't perform NULL check before calling ME_ToUnicode.