Libming is a media-format processing library focused on generating and manipulating SWF (Flash) files, deployed across a narrow but persistent product footprint that spans embedded integrations and specialized multimedia applications. The library's vulnerability surface is characterized by memory-safety weaknesses endemic to a C-based codec parser: out-of-bounds reads and writes, buffer boundary violations, NULL pointer dereferences, and memory-management failures recur as the vendor processes untrusted binary file formats. While the product count remains small, its role in downstream multimedia tools and legacy systems maintains a durable presence in the vulnerability landscape. Defenders should treat Libming as a supply-chain component rather than a high-frequency threat, but exercise caution when the library processes untrusted or attacker-controlled SWF inputs; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libming over time
Signals from CVEs in this vendor scope (124 CVEs).
124 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16705CRITICAL Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a. | Sep 23, 2019 | 9.1 | 28 | NO | NO |
CVE-2019-7582HIGH The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure. | Feb 7, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-9009HIGH In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file. | Mar 25, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-6359HIGH The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other | Jan 27, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-6358HIGH The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or uns | Jan 27, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-6315HIGH The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers t | Jan 25, 2018 | 8.8 | 28 | NO | NO |
CVE-2023-31976HIGH libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c. | May 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2019-9114HIGH Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a. | Feb 25, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-9113HIGH Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a. | Feb 25, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-7581HIGH The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory alloca | Feb 7, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (124 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libming.
Media articles that mention a CVE ID that affects a product developed by Libming — matched by CVE ID, not by vendor name.