Vulnerabilities
124 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-66877 +1 in the same advisory: …66869 | Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8. Buffer overflow vulnerability in function dcputchar in decompile.c in libming 0.4.8. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2025-29484 | An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion. An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — | |
| CVE-2025-26305 | A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. NVD description · AI analysis pending | 8.2 group max | <1% | PoC |
| — | |
| CVE-2024-24149 | A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-24148 | A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-25770 | libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2023-50628 | Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component. Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2023-40781 | Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a crafted .swf file to the makeswf function. Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a crafted .swf file to the makeswf function. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2023-36239 | libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c. libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-31976 | libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c. libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2022-44232 | libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a different vulnerability than CVE-2018-9132 and CVE-2018-20427. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2021-34342 | Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak. Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2021-44590 +1 in the same advisory: …44591 | In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could launch denial of service attacks by submitting a crafted SWF file that exploits this vulnerability. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2020-11895 +1 in the same advisory: …11894 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c. Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c. NVD description · AI analysis pending | 9.1 | 2% | PoC |
| — | |
| CVE-2020-6628 +1 in the same advisory: …6629 | Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c. Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c. NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — |