Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2024-22562

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.
Attacker Value
Unknown

CVE-2023-37644

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.
Attacker Value
Unknown

CVE-2023-29950

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c
Attacker Value
Unknown

CVE-2023-26991

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
SWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.
Attacker Value
Unknown

CVE-2023-27249

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
Attacker Value
Unknown

CVE-2022-46440

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
Attacker Value
Unknown

CVE-2017-16890

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
SWFTools 0.9.2 has a divide-by-zero error in the wav_convert2mono function in lib/wav.c because the align value may be zero.
0
Attacker Value
Unknown

CVE-2017-16868

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.
0
Attacker Value
Unknown

CVE-2017-16797

Disclosure Date: November 12, 2017 (last updated November 26, 2024)
In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, which allows remote attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and application crash) or possibly have unspecified other impact via a crafted PNG file.
0
Attacker Value
Unknown

CVE-2017-16796

Disclosure Date: November 12, 2017 (last updated November 26, 2024)
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a denial of service (invalid write and application crash) or possibly have unspecified other impact via vectors involving an IDAT tag in a crafted PNG file.
0