Vendor CVEs
Swftools
All CVEs
126 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39588 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39587 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39585 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39584 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function namespace_set_hash() located in pool.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39583 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39575 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39563 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39562 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream() located in Stream.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39559 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in GString.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39557 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39556 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39555 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39554 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2021-39553 | Med | 0.36 | 5.5 | 0.01 | Sep 20, 2021 | An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function grealloc() located in gmem.cc. It allows an attacker to cause Denial of Service. | ||
| CVE-2017-16890 | Med | 0.36 | 5.5 | 0.01 | Jul 9, 2018 | SWFTools 0.9.2 has a divide-by-zero error in the wav_convert2mono function in lib/wav.c because the align value may be zero. | ||
| CVE-2017-16868 | Med | 0.36 | 5.5 | 0.01 | Nov 17, 2017 | In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file. | ||
| CVE-2017-1000186 | Med | 0.36 | 5.5 | 0.01 | Nov 17, 2017 | In SWFTools, a stack overflow was found in pdf2swf. | ||
| CVE-2017-1000185 | Med | 0.36 | 5.5 | 0.01 | Nov 17, 2017 | In SWFTools, a memcpy buffer overflow was found in gif2swf. | ||
| CVE-2017-1000182 | Med | 0.36 | 5.5 | 0.01 | Nov 17, 2017 | In SWFTools, a memory leak was found in wav2swf. | ||
| CVE-2017-1000176 | Med | 0.36 | 5.5 | 0.01 | Nov 17, 2017 | In SWFTools, a memcpy buffer overflow was found in swfc. | ||
| CVE-2017-1000174 | Med | 0.36 | 5.5 | 0.01 | Nov 17, 2017 | In SWFTools, an address access exception was found in swfdump swf_GetBits(). | ||
| CVE-2017-16794 | Med | 0.36 | 5.5 | 0.01 | Nov 12, 2017 | The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated… | ||
| CVE-2017-16711 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2017 | The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefinitions in… | ||
| CVE-2024-26337 | Med | 0.28 | 4.3 | 0.01 | Mar 5, 2024 | swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c. | ||
| CVE-2025-6271 | Low | 0.21 | 3.3 | 0.00 | Jun 19, 2025 | A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The… | ||
| CVE-2010-1516 | 0.00 | — | 0.03 | Aug 17, 2010 | Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c. |
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function namespace_set_hash() located in pool.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream() located in Stream.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in GString.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function grealloc() located in gmem.cc. It allows an attacker to cause Denial of Service.
- risk 0.36cvss 5.5epss 0.01
SWFTools 0.9.2 has a divide-by-zero error in the wav_convert2mono function in lib/wav.c because the align value may be zero.
- risk 0.36cvss 5.5epss 0.01
In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.
- risk 0.36cvss 5.5epss 0.01
In SWFTools, a stack overflow was found in pdf2swf.
- risk 0.36cvss 5.5epss 0.01
In SWFTools, a memcpy buffer overflow was found in gif2swf.
- risk 0.36cvss 5.5epss 0.01
In SWFTools, a memory leak was found in wav2swf.
- risk 0.36cvss 5.5epss 0.01
In SWFTools, a memcpy buffer overflow was found in swfc.
- risk 0.36cvss 5.5epss 0.01
In SWFTools, an address access exception was found in swfdump swf_GetBits().
- risk 0.36cvss 5.5epss 0.01
The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated…
- risk 0.36cvss 5.5epss 0.01
The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefinitions in…
- risk 0.28cvss 4.3epss 0.01
swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.
- risk 0.21cvss 3.3epss 0.00
A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The…
- CVE-2010-1516Aug 17, 2010risk 0.00cvss —epss 0.03
Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c.
Page 3 of 3