Vulnerabilities > Libming > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-05-17 | CVE-2018-11225 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact. | 6.8 |
2018-05-15 | CVE-2018-11100 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact. | 6.8 |
2018-05-15 | CVE-2018-11095 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact. | 6.8 |
2018-05-13 | CVE-2018-11017 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact. | 6.8 |
2018-04-01 | CVE-2018-9165 | NULL Pointer Dereference vulnerability in Libming The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file. | 4.3 |
2018-03-30 | CVE-2018-9132 | NULL Pointer Dereference vulnerability in multiple products libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. | 6.5 |
2018-03-23 | CVE-2018-8964 | Use After Free vulnerability in Libming 0.4.8 In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. | 4.3 |
2018-03-23 | CVE-2018-8963 | Use After Free vulnerability in Libming 0.4.8 In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. | 4.3 |
2018-03-23 | CVE-2018-8962 | Use After Free vulnerability in Libming 0.4.8 In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. | 4.3 |
2018-03-23 | CVE-2018-8961 | Use After Free vulnerability in Libming 0.4.8 In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. | 4.3 |