Vendor CVEs
Libming
All CVEs
124 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11895 | Cri | 0.59 | 9.1 | 0.02 | Apr 19, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c. | ||
| CVE-2020-11894 | Cri | 0.59 | 9.1 | 0.02 | Apr 19, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c. | ||
| CVE-2019-16705 | Cri | 0.59 | 9.1 | 0.02 | Sep 23, 2019 | Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a. | ||
| CVE-2023-36239 | Hig | 0.57 | 8.8 | 0.01 | Jun 22, 2023 | libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c. | ||
| CVE-2023-31976 | Hig | 0.57 | 8.8 | 0.01 | May 9, 2023 | libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c. | ||
| CVE-2020-6628 | Hig | 0.57 | 8.8 | 0.02 | Jan 9, 2020 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c. | ||
| CVE-2019-9114 | Hig | 0.57 | 8.8 | 0.01 | Feb 25, 2019 | Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a. | ||
| CVE-2019-9113 | Hig | 0.57 | 8.8 | 0.01 | Feb 25, 2019 | Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a. | ||
| CVE-2019-7582 | Hig | 0.57 | 8.8 | 0.02 | Feb 7, 2019 | The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure. | ||
| CVE-2019-7581 | Hig | 0.57 | 8.8 | 0.02 | Feb 7, 2019 | The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876. | ||
| CVE-2018-20429 | Hig | 0.57 | 8.8 | 0.01 | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165. | ||
| CVE-2018-20428 | Hig | 0.57 | 8.8 | 0.01 | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874. | ||
| CVE-2018-20427 | Hig | 0.57 | 8.8 | 0.01 | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132. | ||
| CVE-2018-20426 | Hig | 0.57 | 8.8 | 0.01 | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866. | ||
| CVE-2018-20425 | Hig | 0.57 | 8.8 | 0.01 | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file. | ||
| CVE-2018-11226 | Hig | 0.57 | 8.8 | 0.02 | May 17, 2018 | The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified… | ||
| CVE-2018-11225 | Hig | 0.57 | 8.8 | 0.02 | May 17, 2018 | The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified… | ||
| CVE-2018-11100 | Hig | 0.57 | 8.8 | 0.02 | May 15, 2018 | The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have… | ||
| CVE-2018-11095 | Hig | 0.57 | 8.8 | 0.02 | May 15, 2018 | The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have… | ||
| CVE-2018-11017 | Hig | 0.57 | 8.8 | 0.01 | May 13, 2018 | The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified… | ||
| CVE-2018-9009 | Hig | 0.57 | 8.8 | 0.02 | Mar 25, 2018 | In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file. | ||
| CVE-2018-7871 | Hig | 0.57 | 8.8 | 0.02 | Mar 8, 2018 | There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to a denial of service or possibly unspecified other impact. | ||
| CVE-2018-6359 | Hig | 0.57 | 8.8 | 0.02 | Jan 27, 2018 | The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file. | ||
| CVE-2018-6358 | Hig | 0.57 | 8.8 | 0.02 | Jan 27, 2018 | The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file. | ||
| CVE-2018-6315 | Hig | 0.57 | 8.8 | 0.02 | Jan 25, 2018 | The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file. | ||
| CVE-2025-26305 | Hig | 0.53 | 8.2 | 0.00 | Feb 20, 2025 | A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. | ||
| CVE-2025-26304 | Hig | 0.53 | 8.2 | 0.00 | Feb 20, 2025 | A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8. | ||
| CVE-2021-31240 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file. | ||
| CVE-2017-7578 | Hig | 0.51 | 7.8 | 0.01 | Apr 7, 2017 | Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incomplete fix for… | ||
| CVE-2016-9831 | Hig | 0.51 | 7.8 | 0.02 | Feb 17, 2017 | Heap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file. | ||
| CVE-2016-9829 | Hig | 0.51 | 7.8 | 0.02 | Feb 17, 2017 | Heap-based buffer overflow in the parseSWF_DEFINEFONT function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file. | ||
| CVE-2025-66877 | Hig | 0.49 | 7.5 | 0.00 | Dec 29, 2025 | Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8. | ||
| CVE-2025-66869 | Hig | 0.49 | 7.5 | 0.00 | Dec 29, 2025 | Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8. | ||
| CVE-2025-29487 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2025 | An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion. | ||
| CVE-2025-29484 | Hig | 0.49 | 7.5 | 0.00 | Mar 27, 2025 | An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion. | ||
| CVE-2024-24148 | Hig | 0.49 | 7.5 | 0.01 | Feb 28, 2024 | A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. | ||
| CVE-2022-44232 | Hig | 0.49 | 7.5 | 0.01 | Apr 26, 2023 | libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427. | ||
| CVE-2018-13066 | Hig | 0.49 | 7.5 | 0.01 | Jul 2, 2018 | There is a memory leak in util/parser.c in libming 0.4.8, which will lead to a denial of service via parseSWF_DEFINEBUTTON2, parseSWF_DEFINEFONT, parseSWF_DEFINEFONTINFO, parseSWF_DEFINELOSSLESS, parseSWF_DEFINESPRITE, parseSWF_DEFINETEXT, parseSWF_DOACTION,… | ||
| CVE-2018-7869 | Hig | 0.49 | 7.5 | 0.02 | Mar 8, 2018 | There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack. | ||
| CVE-2025-29497 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function. | ||
| CVE-2025-29496 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file. | ||
| CVE-2025-29494 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file. | ||
| CVE-2025-29493 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file. | ||
| CVE-2025-29492 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function. | ||
| CVE-2025-29491 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file. | ||
| CVE-2025-29490 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file. | ||
| CVE-2025-29489 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function. | ||
| CVE-2025-29488 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function. | ||
| CVE-2025-29486 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function. | ||
| CVE-2025-29485 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2025 | libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file. |
- risk 0.59cvss 9.1epss 0.02
Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.
- risk 0.59cvss 9.1epss 0.02
Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.
- risk 0.59cvss 9.1epss 0.02
Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.
- risk 0.57cvss 8.8epss 0.01
libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.
- risk 0.57cvss 8.8epss 0.01
libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c.
- risk 0.57cvss 8.8epss 0.02
Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.
- risk 0.57cvss 8.8epss 0.01
Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.
- risk 0.57cvss 8.8epss 0.01
Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.
- risk 0.57cvss 8.8epss 0.02
The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure.
- risk 0.57cvss 8.8epss 0.02
The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876.
- risk 0.57cvss 8.8epss 0.01
libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165.
- risk 0.57cvss 8.8epss 0.01
libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.
- risk 0.57cvss 8.8epss 0.01
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.
- risk 0.57cvss 8.8epss 0.01
libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.
- risk 0.57cvss 8.8epss 0.01
libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.
- risk 0.57cvss 8.8epss 0.02
The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified…
- risk 0.57cvss 8.8epss 0.02
The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified…
- risk 0.57cvss 8.8epss 0.02
The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have…
- risk 0.57cvss 8.8epss 0.02
The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have…
- risk 0.57cvss 8.8epss 0.01
The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified…
- risk 0.57cvss 8.8epss 0.02
In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.
- risk 0.57cvss 8.8epss 0.02
There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to a denial of service or possibly unspecified other impact.
- risk 0.57cvss 8.8epss 0.02
The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.
- risk 0.57cvss 8.8epss 0.02
The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file.
- risk 0.57cvss 8.8epss 0.02
The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.
- risk 0.53cvss 8.2epss 0.00
A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
- risk 0.53cvss 8.2epss 0.00
A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.
- risk 0.51cvss 7.8epss 0.00
An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file.
- risk 0.51cvss 7.8epss 0.01
Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incomplete fix for…
- risk 0.51cvss 7.8epss 0.02
Heap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file.
- risk 0.51cvss 7.8epss 0.02
Heap-based buffer overflow in the parseSWF_DEFINEFONT function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file.
- risk 0.49cvss 7.5epss 0.00
Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8.
- risk 0.49cvss 7.5epss 0.00
Buffer overflow vulnerability in function strcat in asan_interceptors.cpp in libming 0.4.8.
- risk 0.49cvss 7.5epss 0.00
An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.
- risk 0.49cvss 7.5epss 0.00
An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.
- risk 0.49cvss 7.5epss 0.01
A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
- risk 0.49cvss 7.5epss 0.01
libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427.
- risk 0.49cvss 7.5epss 0.01
There is a memory leak in util/parser.c in libming 0.4.8, which will lead to a denial of service via parseSWF_DEFINEBUTTON2, parseSWF_DEFINEFONT, parseSWF_DEFINEFONTINFO, parseSWF_DEFINELOSSLESS, parseSWF_DEFINESPRITE, parseSWF_DEFINETEXT, parseSWF_DOACTION,…
- risk 0.49cvss 7.5epss 0.02
There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.
- risk 0.42cvss 6.5epss 0.00
An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
- risk 0.42cvss 6.5epss 0.00
libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
Page 1 of 3