Vulnerabilities > Swftools > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2024-22914 Use After Free vulnerability in Swftools 0.9.2
A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620.
local
low complexity
swftools CWE-416
5.5
2024-01-19 CVE-2024-22957 Out-of-bounds Read vulnerability in Swftools 0.9.2
swftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.
local
low complexity
swftools CWE-125
5.5
2024-01-11 CVE-2023-37644 Out-of-bounds Write vulnerability in Swftools 0.9.2
SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf.
local
low complexity
swftools CWE-787
5.5
2023-04-27 CVE-2023-29950 Out-of-bounds Write vulnerability in Swftools 0.9.2
swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c
local
low complexity
swftools CWE-787
5.5
2023-03-23 CVE-2023-27249 Out-of-bounds Write vulnerability in Swftools 0.9.2
swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
local
low complexity
swftools CWE-787
5.5
2023-02-24 CVE-2022-46440 Unspecified vulnerability in Swftools 0.9.2
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
local
low complexity
swftools
5.5
2022-10-13 CVE-2022-35080 Out-of-bounds Write vulnerability in Swftools 20211216
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.
local
low complexity
swftools CWE-787
5.5
2022-10-13 CVE-2022-35081 Out-of-bounds Write vulnerability in Swftools 20211216
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.
local
low complexity
swftools CWE-787
5.5
2022-09-21 CVE-2022-35086 Out-of-bounds Write vulnerability in Swftools
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
local
low complexity
swftools CWE-787
5.5
2022-09-21 CVE-2022-35087 NULL Pointer Dereference vulnerability in Swftools
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
local
low complexity
swftools CWE-476
5.5