SwftoolsCVEs & Vulnerabilities

126 CVEs affecting Swftools products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

swftools 126
CVE-2022-35108MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.

17 Aug 2022
5.5
CVSS
CVE-2022-35107MEDIUM

SWFTools commit 772e55a2 was discovered to contain a stack overflow via vfprintf at /stdio-common/vfprintf.c.

17 Aug 2022
5.5
CVSS
CVE-2022-35106MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::computeTableChecksum(unsigned char*, int) at /xpdf/FoFiTrueType.cc.

17 Aug 2022
5.5
CVSS
CVE-2022-35105MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via /bin/png2swf+0x552cea.

17 Aug 2022
5.5
CVSS
CVE-2022-35104MEDIUM

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::reset() at /xpdf/Stream.cc.

17 Aug 2022
5.5
CVSS
CVE-2022-35101MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memset-vec-unaligned-erms.S.

17 Aug 2022
5.5
CVSS
CVE-2022-35100MEDIUM

SWFTools commit 772e55a2 was discovered to contain a segmentation violation via gfxline_getbbox at /lib/gfxtools.c.

17 Aug 2022
6.5
CVSS
CVE-2021-42204HIGH

An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause code execution.

2 Jun 2022
7.8
CVSS
CVE-2021-42203HIGH

An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.

2 Jun 2022
7.8
CVSS
CVE-2021-42202MEDIUM

An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter() located in swffilter.c. It allows an attacker to cause Denial of Service.

2 Jun 2022
5.5
CVSS
CVE-2021-42201HIGH

An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located in rfxswf.c. It allows an attacker to cause code execution.

2 Jun 2022
7.8
CVSS
CVE-2021-42200MEDIUM

An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located in swfdump.c. It allows an attacker to cause Denial of Service.

2 Jun 2022
5.5
CVSS
CVE-2021-42199HIGH

An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_DefineTextCallback() located in swftext.c. It allows an attacker to cause code execution.

2 Jun 2022
7.8
CVSS
CVE-2021-42198MEDIUM

An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause Denial of Service.

2 Jun 2022
5.5
CVSS
CVE-2021-42197HIGH

An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution.

2 Jun 2022
7.8
CVSS
CVE-2021-42196MEDIUM

An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() located in abc.c. It allows an attacker to cause Denial of Service.

2 Jun 2022
5.5
CVSS
CVE-2021-42195HIGH

An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() located in swfdump.c. It allows an attacker to cause code Execution.

2 Jun 2022
7.8
CVSS
CVE-2021-39598MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function callcode() located in code.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39597MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_dump2() located in code.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39596MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_parse() located in code.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39595HIGH

An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function rfx_alloc() located in mem.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39594MEDIUM

Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in swftext.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39593MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo() located in swftext.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39592MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in pool.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39591MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39590MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39589MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function parse_metadata() located in abc.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39588MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39587MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39585MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39584MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function namespace_set_hash() located in pool.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39583MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39582HIGH

An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_GetPlaceObject() located in swfobject.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39579HIGH

An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function string_hash() located in q.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39577HIGH

An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function main() located in swfdump.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39575MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39574HIGH

An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function pool_read() located in pool.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39569HIGH

An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function OpAdvance() located in swfaction.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39564HIGH

An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39563MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39562MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream() located in Stream.cc. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39561HIGH

An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function Gfx::opSetFillColorN() located in Gfx.cc. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39559MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in GString.cc. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39558HIGH

An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function VectorGraphicOutputDev::drawGeneralImage() located in VectorGraphicOutputDev.cc. It allows an attacker to cause code Execution.

20 Sep 2021
7.8
CVSS
CVE-2021-39557MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39556MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39555MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
CVE-2021-39554MEDIUM

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service.

20 Sep 2021
5.5
CVSS
Swftools CVEs & Vulnerabilities — 126 Tracked — Page 2