LibmingCVEs & Vulnerabilities

124 CVEs affecting Libming products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

libming 107ming 17
CVE-2020-6629MEDIUM

Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

9 Jan 2020
6.5
CVSS
CVE-2020-6628HIGH

Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.

9 Jan 2020
8.8
CVSS
CVE-2019-16705CRITICAL

Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.

23 Sep 2019
9.1
CVSS
CVE-2019-12982MEDIUM

Ming (aka libming) 0.4.8 has a heap buffer overflow and underflow in the decompileCAST function in util/decompile.c in libutil.a. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted SWF file.

26 Jun 2019
6.5
CVSS
CVE-2019-12981HIGH

Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.

26 Jun 2019
8.8
CVSS
CVE-2019-12980MEDIUM

In Ming (aka libming) 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the SWFInput_readSBits function in blocks/input.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

26 Jun 2019
6.5
CVSS
CVE-2019-9114HIGH

Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.

25 Feb 2019
8.8
CVSS
CVE-2019-9113HIGH

Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.

25 Feb 2019
8.8
CVSS
CVE-2019-7582HIGH

The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure.

7 Feb 2019
8.8
CVSS
CVE-2019-7581HIGH

The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876.

7 Feb 2019
8.8
CVSS
CVE-2019-3572MEDIUM

An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated with an erroneous call to png_write_row in libpng, an out-of-bounds write might occur for some memory layouts.

2 Jan 2019
6.5
CVSS
CVE-2018-20591MEDIUM

A heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by swftocxx.

30 Dec 2018
6.5
CVSS
CVE-2018-20429HIGH

libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165.

24 Dec 2018
8.8
CVSS
CVE-2018-20428HIGH

libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.

24 Dec 2018
8.8
CVSS
CVE-2018-20427HIGH

libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.

24 Dec 2018
8.8
CVSS
CVE-2018-20426HIGH

libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.

24 Dec 2018
8.8
CVSS
CVE-2018-20425HIGH

libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.

24 Dec 2018
8.8
CVSS
CVE-2018-15871MEDIUM

An invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 2018-03-12. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

25 Aug 2018
6.5
CVSS
CVE-2018-15870MEDIUM

An invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

25 Aug 2018
6.5
CVSS
CVE-2018-13251MEDIUM

In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJPEG2. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

5 Jul 2018
6.5
CVSS
CVE-2018-13250MEDIUM

libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRINGCONCAT. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

5 Jul 2018
6.5
CVSS
CVE-2018-13066HIGH

There is a memory leak in util/parser.c in libming 0.4.8, which will lead to a denial of service via parseSWF_DEFINEBUTTON2, parseSWF_DEFINEFONT, parseSWF_DEFINEFONTINFO, parseSWF_DEFINELOSSLESS, parseSWF_DEFINESPRITE, parseSWF_DEFINETEXT, parseSWF_DOACTION, parseSWF_FILLSTYLEARRAY, parseSWF_FRAMELABEL, parseSWF_LINESTYLEARRAY, parseSWF_PLACEOBJECT2, or parseSWF_SHAPEWITHSTYLE.

2 Jul 2018
7.5
CVSS
CVE-2018-11226HIGH

The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

17 May 2018
8.8
CVSS
CVE-2018-11225HIGH

The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

17 May 2018
8.8
CVSS
CVE-2018-11100HIGH

The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

15 May 2018
8.8
CVSS
CVE-2018-11095HIGH

The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

15 May 2018
8.8
CVSS
CVE-2018-11017HIGH

The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

14 May 2018
8.8
CVSS
CVE-2018-9165MEDIUM

The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file.

1 Apr 2018
6.5
CVSS
CVE-2018-9132MEDIUM

libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

30 Mar 2018
6.5
CVSS
CVE-2018-9009HIGH

In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

25 Mar 2018
8.8
CVSS
CVE-2018-8964MEDIUM

In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

24 Mar 2018
6.5
CVSS
CVE-2018-8963MEDIUM

In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

24 Mar 2018
6.5
CVSS
CVE-2018-8962MEDIUM

In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

24 Mar 2018
6.5
CVSS
CVE-2018-8961MEDIUM

In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

24 Mar 2018
6.5
CVSS
CVE-2018-8807MEDIUM

In libming 0.4.8, these is a use-after-free in the function decompileCALLFUNCTION of decompile.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

20 Mar 2018
6.5
CVSS
CVE-2018-8806MEDIUM

In libming 0.4.8, there is a use-after-free in the decompileArithmeticOp function of decompile.c. Remote attackers could use this vulnerability to cause a denial-of-service via a crafted swf file.

20 Mar 2018
6.5
CVSS
CVE-2018-7877MEDIUM

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A Crafted input will lead to a denial of service attack.

8 Mar 2018
6.5
CVSS
CVE-2018-7876MEDIUM

In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file.

8 Mar 2018
6.5
CVSS
CVE-2018-7875MEDIUM

There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.

8 Mar 2018
6.5
CVSS
CVE-2018-7874MEDIUM

An invalid memory address dereference was discovered in strlenext in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

8 Mar 2018
6.5
CVSS
CVE-2018-7873MEDIUM

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for INTEGER data. A Crafted input will lead to a denial of service attack.

8 Mar 2018
6.5
CVSS
CVE-2018-7872MEDIUM

An invalid memory address dereference was discovered in the function getName in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

8 Mar 2018
6.5
CVSS
CVE-2018-7871HIGH

There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to a denial of service or possibly unspecified other impact.

8 Mar 2018
8.8
CVSS
CVE-2018-7870MEDIUM

An invalid memory address dereference was discovered in getString in util/decompile.c in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

8 Mar 2018
6.5
CVSS
CVE-2018-7869HIGH

There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.

8 Mar 2018
7.5
CVSS
CVE-2018-7868MEDIUM

There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.

8 Mar 2018
6.5
CVSS
CVE-2018-7867MEDIUM

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 during a RegisterNumber sprintf. A Crafted input will lead to a denial of service attack.

8 Mar 2018
6.5
CVSS
CVE-2018-7866MEDIUM

A NULL pointer dereference was discovered in newVar3 in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

8 Mar 2018
6.5
CVSS