Vulnerabilities
125 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-6271 | A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 1.9 | <1% | PoC ×2 |
| — | |
| CVE-2024-28458 | Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/act Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-26339 | swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a. swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a. NVD description · AI analysis pending | 9.1 group max | <1% | PoC |
| — | |
| CVE-2024-25165 | A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex. A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2024-22915 | A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution. NVD description · AI analysis pending | 7.8 group max | <1% | PoC |
| — | |
| CVE-2023-37644 | SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2023-29950 | swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2023-26991 | SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c. SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2023-27249 | swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c. swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c. NVD description · AI analysis pending | 5.5 | <1% | PoC ×3 |
| — | |
| CVE-2022-46440 | ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c. ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2022-35081 +1 in the same advisory: …35080 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c. SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2022-35096 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2022-35090 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:. SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2022-40009 +1 in the same advisory: …40008 | SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c. SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-35114 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c. SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — |