VYPR

Libming

by Libming

Source repositories

CVEs (12)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-7578Hig0.517.80.00Apr 7, 2017Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incomplete fix for CVE-2016-9831.
CVE-2016-9831Hig0.517.80.00Feb 17, 2017Heap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file.
CVE-2017-16883Med0.426.50.00Nov 18, 2017The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.
CVE-2017-9989Med0.426.50.01Jun 28, 2017util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.
CVE-2017-9988Med0.426.50.01Jun 28, 2017The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.
CVE-2017-8782Med0.426.50.00May 31, 2017The readString function in util/read.c and util/old/read.c in libming 0.4.8 allows remote attackers to cause a denial of service via a large file that is mishandled by listswf, listaction, etc. This occurs because of an integer overflow that leads to a memory allocation error.
CVE-2016-9266Med0.426.50.01Mar 23, 2017listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.
CVE-2017-16898Med0.365.50.00Nov 20, 2017The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.
CVE-2016-9265Med0.365.50.00Mar 23, 2017The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.
CVE-2016-9264Med0.365.50.00Mar 23, 2017Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
CVE-2025-668770.000.00Dec 29, 2025Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
CVE-2025-668690.000.00Dec 29, 2025Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.