swftools records
126 published records for vendor swftools.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 1.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write40
- CWE-476 NULL Pointer Dereference35
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-125 Out-of-bounds Read10
- CWE-416 Use After Free9
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
126 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-40009No exploit | SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.swftools · swftools · CWE-416 | Critical9.8 | — | 1.2% | Sep 20, 2022 |
39Monitor | CVE-2022-40008No exploit | SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.swftools · swftools · CWE-787 | Critical9.8 | — | 1.2% | Sep 20, 2022 |
38Monitor | CVE-2010-1516No exploit | Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getswftools · swftools · CWE-189 | Critical9.3 | — | 3.5% | Aug 17, 2010 |
36Monitor | CVE-2017-8400No exploit | In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755.swftools · swftools · CWE-787 | High8.8 | — | 2.1% | May 1, 2017 |
36Monitor | CVE-2017-9924No exploit | In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a craftedswftools · swftools · CWE-119 | High8.8 | — | 2.0% | Jul 5, 2017 |
36Monitor | CVE-2017-9925No exploit | In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a craftedswftools · swftools · CWE-119 | High8.8 | — | 2.0% | Jul 5, 2017 |
36Monitor | CVE-2024-26339No exploit | swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.swftools · swftools | Critical9.1 | — | 0.8% | Mar 5, 2024 |
35Monitor | CVE-2017-11101No exploit | When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/swftools · swftools · CWE-476 | High8.8 | — | 1.4% | Jul 7, 2017 |
35Monitor | CVE-2017-11100No exploit | When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in liswftools · swftools · CWE-476 | High8.8 | — | 1.4% | Jul 7, 2017 |
35Monitor | CVE-2017-11099No exploit | When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wswftools · swftools · CWE-20 | High8.8 | — | 1.4% | Jul 7, 2017 |
35Monitor | CVE-2017-11098No exploit | When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.swftools · swftools · CWE-20 | High8.8 | — | 1.4% | Jul 7, 2017 |
35Monitor | CVE-2017-11096No exploit | When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_DeleteFilter() function in swftools · swftools · CWE-476 | High8.8 | — | 1.4% | Jul 7, 2017 |
35Monitor | CVE-2017-11097No exploit | When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.swftools · swftools · CWE-476 | High8.8 | — | 1.4% | Jul 7, 2017 |
35Monitor | CVE-2017-9927No exploit | In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impaswftools · swftools · CWE-119 | High8.8 | — | 1.3% | Jul 5, 2017 |
35Monitor | CVE-2017-9926No exploit | In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impaswftools · swftools · CWE-119 | High8.8 | — | 1.3% | Jul 5, 2017 |
31Monitor | CVE-2017-7698No exploit | A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF docswftools · swftools · CWE-416 | High7.8 | — | 1.7% | May 10, 2017 |
31Monitor | CVE-2017-16796No exploit | In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to caswftools · swftools · CWE-119 | High7.8 | — | 1.3% | Nov 12, 2017 |
31Monitor | CVE-2021-42204No exploit | An issue was discovered in swftools through 20201222.swftools · swftools · CWE-787 | High7.8 | — | 1.3% | Jun 2, 2022 |
31Monitor | CVE-2017-16797No exploit | In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, wswftools · swftools · CWE-190 | High7.8 | — | 1.2% | Nov 12, 2017 |
31Monitor | CVE-2017-16793No exploit | The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a dswftools · swftools · CWE-119 | High7.8 | — | 1.2% | Nov 12, 2017 |
31Monitor | CVE-2021-42203No exploit | An issue was discovered in swftools through 20201222.swftools · swftools · CWE-416 | High7.8 | — | 1.2% | Jun 2, 2022 |
31Monitor | CVE-2021-42201No exploit | An issue was discovered in swftools through 20201222.swftools · swftools · CWE-787 | High7.8 | — | 1.1% | Jun 2, 2022 |
31Monitor | CVE-2021-42197No exploit | An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used.swftools · swftools · CWE-401 | High7.8 | — | 1.1% | Jun 2, 2022 |
31Monitor | CVE-2021-39582No exploit | An issue was discovered in swftools through 20200710.swftools · swftools · CWE-787 | High7.8 | — | 1.1% | Sep 20, 2021 |
31Monitor | CVE-2021-39579No exploit | An issue was discovered in swftools through 20200710.swftools · swftools · CWE-787 | High7.8 | — | 1.1% | Sep 20, 2021 |
- CVE-2022-4000939Monitor
SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.
CriticalCVSS 9.8No exploitEPSS 1%swftools · swftoolsSep 20, 2022
- CVE-2022-4000839Monitor
SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
CriticalCVSS 9.8No exploitEPSS 1%swftools · swftoolsSep 20, 2022
- CVE-2010-151638Monitor
Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the get
CriticalCVSS 9.3No exploitEPSS 3%swftools · swftoolsAug 17, 2010
- CVE-2017-840036Monitor
In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755.
HighCVSS 8.8No exploitEPSS 2%swftools · swftoolsMay 1, 2017
- CVE-2017-992436Monitor
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted
HighCVSS 8.8No exploitEPSS 2%swftools · swftoolsJul 5, 2017
- CVE-2017-992536Monitor
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted
HighCVSS 8.8No exploitEPSS 2%swftools · swftoolsJul 5, 2017
- CVE-2024-2633936Monitor
swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.
CriticalCVSS 9.1No exploitEPSS 1%swftools · swftoolsMar 5, 2024
- CVE-2017-1110135Monitor
When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 7, 2017
- CVE-2017-1110035Monitor
When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in li
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 7, 2017
- CVE-2017-1109935Monitor
When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/w
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 7, 2017
- CVE-2017-1109835Monitor
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 7, 2017
- CVE-2017-1109635Monitor
When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_DeleteFilter() function in
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 7, 2017
- CVE-2017-1109735Monitor
When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 7, 2017
- CVE-2017-992735Monitor
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impa
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 5, 2017
- CVE-2017-992635Monitor
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impa
HighCVSS 8.8No exploitEPSS 1%swftools · swftoolsJul 5, 2017
- CVE-2017-769831Monitor
A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF doc
HighCVSS 7.8No exploitEPSS 2%swftools · swftoolsMay 10, 2017
- CVE-2017-1679631Monitor
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to ca
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsNov 12, 2017
- CVE-2021-4220431Monitor
An issue was discovered in swftools through 20201222.
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsJun 2, 2022
- CVE-2017-1679731Monitor
In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, w
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsNov 12, 2017
- CVE-2017-1679331Monitor
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a d
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsNov 12, 2017
- CVE-2021-4220331Monitor
An issue was discovered in swftools through 20201222.
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsJun 2, 2022
- CVE-2021-4220131Monitor
An issue was discovered in swftools through 20201222.
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsJun 2, 2022
- CVE-2021-4219731Monitor
An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used.
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsJun 2, 2022
- CVE-2021-3958231Monitor
An issue was discovered in swftools through 20200710.
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsSep 20, 2021
- CVE-2021-3957931Monitor
An issue was discovered in swftools through 20200710.
HighCVSS 7.8No exploitEPSS 1%swftools · swftoolsSep 20, 2021