SwftoolsCVEs & Vulnerabilities

126 CVEs affecting Swftools products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

swftools 126
CVE-2025-6271LOW

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

19 Jun 2025
3.3
CVSS
CVE-2024-28458HIGH

Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

12 Apr 2024
7.5
CVSS
CVE-2024-26339CRITICAL

swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

5 Mar 2024
9.1
CVSS
CVE-2024-26337MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.

5 Mar 2024
4.3
CVSS
CVE-2024-26335MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

5 Mar 2024
5.5
CVSS
CVE-2024-26334MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib/action/actioncompiler.c.

5 Mar 2024
6.2
CVSS
CVE-2024-26333MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.

5 Mar 2024
5.5
CVSS
CVE-2024-25165HIGH

A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

14 Feb 2024
7.8
CVSS
CVE-2024-22957MEDIUM

swftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.

19 Jan 2024
5.5
CVSS
CVE-2024-22956HIGH

swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838

19 Jan 2024
7.8
CVSS
CVE-2024-22955HIGH

swftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576.

19 Jan 2024
7.8
CVSS
CVE-2024-22919HIGH

swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.

19 Jan 2024
7.8
CVSS
CVE-2024-22915HIGH

A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.

19 Jan 2024
7.8
CVSS
CVE-2024-22914MEDIUM

A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of service.

19 Jan 2024
5.5
CVSS
CVE-2024-22913HIGH

A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.

19 Jan 2024
7.8
CVSS
CVE-2024-22912HIGH

A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.

19 Jan 2024
7.8
CVSS
CVE-2024-22911HIGH

A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.

19 Jan 2024
7.8
CVSS
CVE-2024-22920HIGH

swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.

19 Jan 2024
7.8
CVSS
CVE-2024-22562HIGH

swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.

19 Jan 2024
7.8
CVSS
CVE-2023-37644MEDIUM

SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.

11 Jan 2024
5.5
CVSS
CVE-2023-29950MEDIUM

swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c

27 Apr 2023
5.5
CVSS
CVE-2023-26991HIGH

SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.

4 Apr 2023
7.8
CVSS
CVE-2023-27249MEDIUM

swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.

23 Mar 2023
5.5
CVSS
CVE-2022-46440MEDIUM

ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.

24 Feb 2023
5.5
CVSS
CVE-2022-35081MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.

13 Oct 2022
5.5
CVSS
CVE-2022-35080MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.

13 Oct 2022
5.5
CVSS
CVE-2022-35099MEDIUM

SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.

23 Sep 2022
5.5
CVSS
CVE-2022-35098MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.

23 Sep 2022
5.5
CVSS
CVE-2022-35097MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.

23 Sep 2022
5.5
CVSS
CVE-2022-35096MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

23 Sep 2022
5.5
CVSS
CVE-2022-35095MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.

23 Sep 2022
5.5
CVSS
CVE-2022-35094MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.

23 Sep 2022
5.5
CVSS
CVE-2022-35093MEDIUM

SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.

23 Sep 2022
5.5
CVSS
CVE-2022-35092MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c.

23 Sep 2022
5.5
CVSS
CVE-2022-35091MEDIUM

SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf/Stream.cc.ow()

23 Sep 2022
5.5
CVSS
CVE-2022-35090MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:.

21 Sep 2022
5.5
CVSS
CVE-2022-35089MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.

21 Sep 2022
5.5
CVSS
CVE-2022-35088MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swftools/src/src/gif2swf.c.

21 Sep 2022
5.5
CVSS
CVE-2022-35087MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.

21 Sep 2022
5.5
CVSS
CVE-2022-35086MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.

21 Sep 2022
5.5
CVSS
CVE-2022-35085MEDIUM

SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

21 Sep 2022
5.5
CVSS
CVE-2022-40009CRITICAL

SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.

20 Sep 2022
9.8
CVSS
CVE-2022-40008CRITICAL

SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.

20 Sep 2022
9.8
CVSS
CVE-2022-35114MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c.

17 Aug 2022
5.5
CVSS
CVE-2022-35113MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via swf_DefineLosslessBitsTagToImage at /modules/swfbits.c.

17 Aug 2022
5.5
CVSS
CVE-2022-35111MEDIUM

SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer::StackDepotNode::hash(__sanitizer::StackTrace const&) at /sanitizer_common/sanitizer_stackdepot.cpp.

17 Aug 2022
5.5
CVSS
CVE-2022-35110MEDIUM

SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

17 Aug 2022
5.5
CVSS
CVE-2022-35109MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c.

17 Aug 2022
5.5
CVSS
← PrevPage 1 / 3Next →