ZeroHour

Vulnerabilities

125 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-6271
A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2.

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
1.9<1% PoC ×2
  • swftools swftools
CVE-2024-28458
Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/act

Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

NVD description · AI analysis pending
7.5<1% PoC
  • swftools swftools
CVE-2024-26339
+4 in the same advisory: …26334 …26335 …26333 …26337
swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • swftools swftools
CVE-2024-25165
A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

NVD description · AI analysis pending
7.8<1% PoC
  • swftools swftools
CVE-2024-22915
A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193.

A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • swftools swftools
CVE-2023-37644
SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf.

SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.

NVD description · AI analysis pending
5.5<1% PoC
  • swftools swftools
CVE-2023-29950
swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c

swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c

NVD description · AI analysis pending
5.5<1% PoC
  • swftools swftools
CVE-2023-26991
SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.

SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.

NVD description · AI analysis pending
7.8<1% PoC
  • swftools swftools
CVE-2023-27249
swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.

swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.

NVD description · AI analysis pending
5.5<1% PoC ×3
  • swftools swftools
CVE-2022-46440
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.

ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • swftools swftools
CVE-2022-35081
+1 in the same advisory: …35080
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • swftools swftools
CVE-2022-35096
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • swftools swftools
CVE-2022-35090
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • swftools swftools
CVE-2022-40009
+1 in the same advisory: …40008
SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.

SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.

NVD description · AI analysis pending
9.81% PoC
  • swftools swftools
CVE-2022-35114
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c.

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c.

NVD description · AI analysis pending
5.5<1% PoC
  • swftools swftools