RSS   Vulnerabilities for 'Libming'   RSS

2018-05-17
 
CVE-2018-11226

CWE-119
 

 
The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

 
 
CVE-2018-11225

CWE-119
 

 
The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

 
2018-05-14
 
CVE-2018-11100

CWE-19
 

 
The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

 
 
CVE-2018-11095

CWE-19
 

 
The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

 
2018-05-13
 
CVE-2018-11017

CWE-119
 

 
The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.

 
2018-04-01
 
CVE-2018-9165

CWE-476
 

 
The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file.

 
2018-03-30
 
CVE-2018-9132

CWE-476
 

 
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

 
2018-03-24
 
CVE-2018-9009

CWE-416
 

 
In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

 
2018-03-23
 
CVE-2018-8964

CWE-416
 

 
In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

 
 
CVE-2018-8963

CWE-416
 

 
In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

 


Copyright 2018, cxsecurity.com

 

Back to Top