Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libming

First CVE: Feb 17, 2017Active for: 9 yearsTotal CVEs: 124
25.7
VTI Score
Low

Libming is a media-format processing library focused on generating and manipulating SWF (Flash) files, deployed across a narrow but persistent product footprint that spans embedded integrations and specialized multimedia applications. The library's vulnerability surface is characterized by memory-safety weaknesses endemic to a C-based codec parser: out-of-bounds reads and writes, buffer boundary violations, NULL pointer dereferences, and memory-management failures recur as the vendor processes untrusted binary file formats. While the product count remains small, its role in downstream multimedia tools and legacy systems maintains a durable presence in the vulnerability landscape. Defenders should treat Libming as a supply-chain component rather than a high-frequency threat, but exercise caution when the library processes untrusted or attacker-controlled SWF inputs; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
124
Total CVEs
More Total CVEs than 99% of tracked vendors
7.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libming over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 17, 2017
9 years ago
Most Recent CVE
Dec 29, 2025
207 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (124 CVEs).

124 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16705CRITICAL
Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.
Sep 23, 20199.128NONO
CVE-2019-7582HIGH
The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure.
Feb 7, 20198.828NONO
CVE-2018-9009HIGH
In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.
Mar 25, 20188.828NONO
CVE-2018-6359HIGH
The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other
Jan 27, 20188.828NONO
CVE-2018-6358HIGH
The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or uns
Jan 27, 20188.828NONO
CVE-2018-6315HIGH
The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers t
Jan 25, 20188.828NONO
CVE-2023-31976HIGH
libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c.
May 9, 20238.827NONO
CVE-2019-9114HIGH
Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a.
Feb 25, 20198.827NONO
CVE-2019-9113HIGH
Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.
Feb 25, 20198.827NONO
CVE-2019-7581HIGH
The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory alloca
Feb 7, 20198.827NONO
View all 124 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products124 CVEs
67%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local19 (15.3%)
Network105 (84.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low124 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (15.3%)
Unknown0 (0.0%)
Required105 (84.7%)
Privileges Required
Low5 (4.0%)
High0 (0.0%)
None119 (96.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (124 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libming.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libming — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libming's Products

View all 2 CNAs →

Top CWEs