Vulnerabilities > Libming > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-05-17 CVE-2018-11225 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
network
libming CWE-119
6.8
2018-05-15 CVE-2018-11100 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
network
libming CWE-119
6.8
2018-05-15 CVE-2018-11095 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
network
libming CWE-119
6.8
2018-05-13 CVE-2018-11017 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
network
libming CWE-119
6.8
2018-04-01 CVE-2018-9165 NULL Pointer Dereference vulnerability in Libming
The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file.
network
libming CWE-476
4.3
2018-03-30 CVE-2018-9132 NULL Pointer Dereference vulnerability in multiple products
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file.
network
low complexity
libming debian CWE-476
6.5
2018-03-23 CVE-2018-8964 Use After Free vulnerability in Libming 0.4.8
In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free.
network
libming CWE-416
4.3
2018-03-23 CVE-2018-8963 Use After Free vulnerability in Libming 0.4.8
In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free.
network
libming CWE-416
4.3
2018-03-23 CVE-2018-8962 Use After Free vulnerability in Libming 0.4.8
In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free.
network
libming CWE-416
4.3
2018-03-23 CVE-2018-8961 Use After Free vulnerability in Libming 0.4.8
In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free.
network
libming CWE-416
4.3