VYPR

Swftools

by Swftools

Source repositories

CVEs (126)

  • CVE-2017-1000174MedNov 17, 2017
    risk 0.36cvss 5.5epss 0.01

    In SWFTools, an address access exception was found in swfdump swf_GetBits().

  • CVE-2017-16794MedNov 12, 2017
    risk 0.36cvss 5.5epss 0.01

    The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated…

  • CVE-2017-16711MedNov 9, 2017
    risk 0.36cvss 5.5epss 0.01

    The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefinitions in…

  • CVE-2024-26337MedMar 5, 2024
    risk 0.28cvss 4.3epss 0.01

    swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.

  • CVE-2025-6271LowJun 19, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The…

  • CVE-2010-1516Aug 17, 2010
    risk 0.00cvss epss 0.03

    Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c.

Page 7 of 7