libming CVE Vulnerabilities & Metrics

Focus on libming vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About libming Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with libming. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total libming CVEs: 98
Earliest CVE date: 17 Feb 2017, 02:59 UTC
Latest CVE date: 29 Feb 2024, 01:44 UTC

Latest CVE reference: CVE-2024-24150

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical libming CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.41

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 85
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS libming CVEs

These are the five CVEs with the highest CVSS scores for libming, sorted by severity first and recency.

All CVEs for libming

CVE-2024-24150 libming vulnerability CVSS: 0 29 Feb 2024, 01:44 UTC

A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

CVE-2024-24149 libming vulnerability CVSS: 0 29 Feb 2024, 01:44 UTC

A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

CVE-2024-24147 libming vulnerability CVSS: 0 29 Feb 2024, 01:44 UTC

A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

CVE-2024-24146 libming vulnerability CVSS: 0 29 Feb 2024, 01:44 UTC

A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

CVE-2023-50628 libming vulnerability CVSS: 0 20 Dec 2023, 09:15 UTC

Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component.

CVE-2023-40781 libming vulnerability CVSS: 0 28 Aug 2023, 22:15 UTC

Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a crafted .swf file to the makeswf function.

CVE-2023-36239 libming vulnerability CVSS: 0 22 Jun 2023, 19:15 UTC

libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.

CVE-2023-30085 libming vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the cws2fws function in util/decompile.c.

CVE-2023-30084 libming vulnerability CVSS: 0 09 May 2023, 16:15 UTC

An issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal function in util/decompile.c.

CVE-2023-30083 libming vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Buffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the newVar_N in util/decompile.c.

CVE-2021-31240 libming vulnerability CVSS: 0 09 May 2023, 16:15 UTC

An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file.

CVE-2023-31976 libming vulnerability CVSS: 0 09 May 2023, 14:15 UTC

libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c.

CVE-2022-44232 libming vulnerability CVSS: 0 26 Apr 2023, 19:15 UTC

libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427.

CVE-2021-34342 libming vulnerability CVSS: 4.3 10 Mar 2022, 17:42 UTC

Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak.

CVE-2021-34341 libming vulnerability CVSS: 4.3 10 Mar 2022, 17:42 UTC

Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.

CVE-2021-34340 libming vulnerability CVSS: 4.3 10 Mar 2022, 17:42 UTC

Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

CVE-2021-34339 libming vulnerability CVSS: 4.3 10 Mar 2022, 17:42 UTC

Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

CVE-2021-34338 libming vulnerability CVSS: 4.3 10 Mar 2022, 17:42 UTC

Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.

CVE-2021-44591 libming vulnerability CVSS: 4.3 06 Jan 2022, 14:15 UTC

In libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denial-of-service attacks via a crafted SWF file.

CVE-2021-44590 libming vulnerability CVSS: 4.3 06 Jan 2022, 14:15 UTC

In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could launch denial of service attacks by submitting a crafted SWF file that exploits this vulnerability.

CVE-2020-11895 libming vulnerability CVSS: 6.4 19 Apr 2020, 19:15 UTC

Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.

CVE-2020-11894 libming vulnerability CVSS: 6.4 19 Apr 2020, 19:15 UTC

Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.

CVE-2020-6629 libming vulnerability CVSS: 4.3 09 Jan 2020, 02:15 UTC

Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

CVE-2020-6628 libming vulnerability CVSS: 6.8 09 Jan 2020, 02:15 UTC

Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.

CVE-2019-16705 libming vulnerability CVSS: 6.4 23 Sep 2019, 05:15 UTC

Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.

CVE-2019-12982 libming vulnerability CVSS: 4.3 26 Jun 2019, 18:15 UTC

Ming (aka libming) 0.4.8 has a heap buffer overflow and underflow in the decompileCAST function in util/decompile.c in libutil.a. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted SWF file.

CVE-2019-12981 libming vulnerability CVSS: 6.8 26 Jun 2019, 18:15 UTC

Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.

CVE-2019-12980 libming vulnerability CVSS: 4.3 26 Jun 2019, 18:15 UTC

In Ming (aka libming) 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the SWFInput_readSBits function in blocks/input.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

CVE-2019-9114 libming vulnerability CVSS: 6.8 25 Feb 2019, 04:29 UTC

Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.

CVE-2019-9113 libming vulnerability CVSS: 6.8 25 Feb 2019, 04:29 UTC

Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.

CVE-2019-7582 libming vulnerability CVSS: 6.8 07 Feb 2019, 18:29 UTC

The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure.

CVE-2019-7581 libming vulnerability CVSS: 6.8 07 Feb 2019, 18:29 UTC

The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876.

CVE-2019-3572 libming vulnerability CVSS: 4.3 02 Jan 2019, 15:29 UTC

An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated with an erroneous call to png_write_row in libpng, an out-of-bounds write might occur for some memory layouts.

CVE-2018-20591 libming vulnerability CVSS: 4.3 30 Dec 2018, 18:29 UTC

A heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by swftocxx.

CVE-2018-20429 libming vulnerability CVSS: 6.8 24 Dec 2018, 05:29 UTC

libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165.

CVE-2018-20428 libming vulnerability CVSS: 6.8 24 Dec 2018, 05:29 UTC

libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.

CVE-2018-20427 libming vulnerability CVSS: 6.8 24 Dec 2018, 05:29 UTC

libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.

CVE-2018-20426 libming vulnerability CVSS: 6.8 24 Dec 2018, 05:29 UTC

libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.

CVE-2018-20425 libming vulnerability CVSS: 6.8 24 Dec 2018, 05:29 UTC

libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.

CVE-2018-15871 libming vulnerability CVSS: 4.3 25 Aug 2018, 19:29 UTC

An invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 2018-03-12. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVE-2018-15870 libming vulnerability CVSS: 4.3 25 Aug 2018, 19:29 UTC

An invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVE-2018-13251 libming vulnerability CVSS: 4.3 05 Jul 2018, 14:29 UTC

In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJPEG2. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

CVE-2018-13250 libming vulnerability CVSS: 4.3 05 Jul 2018, 14:29 UTC

libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRINGCONCAT. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-13066 libming vulnerability CVSS: 5.0 02 Jul 2018, 17:29 UTC

There is a memory leak in util/parser.c in libming 0.4.8, which will lead to a denial of service via parseSWF_DEFINEBUTTON2, parseSWF_DEFINEFONT, parseSWF_DEFINEFONTINFO, parseSWF_DEFINELOSSLESS, parseSWF_DEFINESPRITE, parseSWF_DEFINETEXT, parseSWF_DOACTION, parseSWF_FILLSTYLEARRAY, parseSWF_FRAMELABEL, parseSWF_LINESTYLEARRAY, parseSWF_PLACEOBJECT2, or parseSWF_SHAPEWITHSTYLE.

CVE-2018-11226 libming vulnerability CVSS: 6.8 17 May 2018, 04:29 UTC

The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

CVE-2018-11225 libming vulnerability CVSS: 6.8 17 May 2018, 04:29 UTC

The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

CVE-2018-11100 libming vulnerability CVSS: 6.8 15 May 2018, 01:29 UTC

The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

CVE-2018-11095 libming vulnerability CVSS: 6.8 15 May 2018, 00:29 UTC

The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

CVE-2018-11017 libming vulnerability CVSS: 6.8 13 May 2018, 21:29 UTC

The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

CVE-2018-9165 libming vulnerability CVSS: 4.3 01 Apr 2018, 18:29 UTC

The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file.

CVE-2018-9132 libming vulnerability CVSS: 4.3 30 Mar 2018, 08:29 UTC

libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-9009 libming vulnerability CVSS: 6.8 25 Mar 2018, 03:29 UTC

In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

CVE-2018-8964 libming vulnerability CVSS: 4.3 23 Mar 2018, 21:29 UTC

In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-8963 libming vulnerability CVSS: 4.3 23 Mar 2018, 21:29 UTC

In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-8962 libming vulnerability CVSS: 4.3 23 Mar 2018, 21:29 UTC

In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-8961 libming vulnerability CVSS: 4.3 23 Mar 2018, 21:29 UTC

In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-8807 libming vulnerability CVSS: 4.3 20 Mar 2018, 05:29 UTC

In libming 0.4.8, these is a use-after-free in the function decompileCALLFUNCTION of decompile.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2018-8806 libming vulnerability CVSS: 4.3 20 Mar 2018, 05:29 UTC

In libming 0.4.8, there is a use-after-free in the decompileArithmeticOp function of decompile.c. Remote attackers could use this vulnerability to cause a denial-of-service via a crafted swf file.

CVE-2018-7877 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A Crafted input will lead to a denial of service attack.

CVE-2018-7876 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file.

CVE-2018-7875 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.

CVE-2018-7874 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

An invalid memory address dereference was discovered in strlenext in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVE-2018-7873 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for INTEGER data. A Crafted input will lead to a denial of service attack.

CVE-2018-7872 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

An invalid memory address dereference was discovered in the function getName in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVE-2018-7871 libming vulnerability CVSS: 6.8 08 Mar 2018, 18:29 UTC

There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVE-2018-7870 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

An invalid memory address dereference was discovered in getString in util/decompile.c in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVE-2018-7869 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.

CVE-2018-7868 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.

CVE-2018-7867 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 during a RegisterNumber sprintf. A Crafted input will lead to a denial of service attack.

CVE-2018-7866 libming vulnerability CVSS: 4.3 08 Mar 2018, 18:29 UTC

A NULL pointer dereference was discovered in newVar3 in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVE-2018-6359 libming vulnerability CVSS: 6.8 27 Jan 2018, 21:29 UTC

The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.

CVE-2018-6358 libming vulnerability CVSS: 6.8 27 Jan 2018, 21:29 UTC

The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file.

CVE-2018-6315 libming vulnerability CVSS: 6.8 25 Jan 2018, 22:29 UTC

The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.

CVE-2018-5294 libming vulnerability CVSS: 4.3 08 Jan 2018, 07:29 UTC

In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

CVE-2018-5251 libming vulnerability CVSS: 4.3 05 Jan 2018, 20:29 UTC

In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file.

CVE-2017-16898 libming vulnerability CVSS: 4.3 20 Nov 2017, 17:29 UTC

The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.

CVE-2017-16883 libming vulnerability CVSS: 4.3 18 Nov 2017, 18:29 UTC

The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.

CVE-2017-11734 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11733 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11732 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11731 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11730 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1474) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11729 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11728 libming vulnerability CVSS: 4.3 29 Jul 2017, 05:29 UTC

A heap-based buffer over-read was found in the function OpCode (called from decompileSETMEMBER) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11705 libming vulnerability CVSS: 4.3 28 Jul 2017, 05:29 UTC

A memory leak was found in the function parseSWF_SHAPEWITHSTYLE in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11704 libming vulnerability CVSS: 4.3 28 Jul 2017, 05:29 UTC

A heap-based buffer over-read was found in the function decompileIF in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-11703 libming vulnerability CVSS: 4.3 28 Jul 2017, 05:29 UTC

A memory leak vulnerability was found in the function parseSWF_DOACTION in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-9989 libming vulnerability CVSS: 4.3 28 Jun 2017, 06:29 UTC

util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.

CVE-2017-9988 libming vulnerability CVSS: 4.3 28 Jun 2017, 06:29 UTC

The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.

CVE-2017-8782 libming vulnerability CVSS: 4.3 31 May 2017, 04:29 UTC

The readString function in util/read.c and util/old/read.c in libming 0.4.8 allows remote attackers to cause a denial of service via a large file that is mishandled by listswf, listaction, etc. This occurs because of an integer overflow that leads to a memory allocation error.

CVE-2017-7578 libming vulnerability CVSS: 6.8 07 Apr 2017, 04:59 UTC

Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incomplete fix for CVE-2016-9831.

CVE-2016-9266 libming vulnerability CVSS: 4.3 23 Mar 2017, 18:59 UTC

listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.

CVE-2016-9265 libming vulnerability CVSS: 4.3 23 Mar 2017, 18:59 UTC

The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

CVE-2016-9264 libming vulnerability CVSS: 4.3 23 Mar 2017, 18:59 UTC

Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.

CVE-2016-9831 libming vulnerability CVSS: 6.8 17 Feb 2017, 02:59 UTC

Heap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file.

CVE-2016-9829 libming vulnerability CVSS: 6.8 17 Feb 2017, 02:59 UTC

Heap-based buffer overflow in the parseSWF_DEFINEFONT function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have unspecified impact via a crafted SWF file.

CVE-2016-9828 libming vulnerability CVSS: 4.3 17 Feb 2017, 02:59 UTC

The dumpBuffer function in read.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SWF file.

CVE-2016-9827 libming vulnerability CVSS: 4.3 17 Feb 2017, 02:59 UTC

The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (buffer over-read) via a crafted SWF file.