Ming
Vendor:
First CVE: Jul 28, 2017 · Active for 8 years
17
Total CVEs
More Total CVEs than 93% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ming over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2017
8 years ago
Most Recent CVE
Mar 10, 2022
1,597 days ago
CVE Severity & Scoring
Ming17 CVEs
88%
12%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (41.2%)
Network10 (58.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required17 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None17 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9114HIGH Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in libutil.a. | Feb 25, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-9113HIGH Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a. | Feb 25, 2019 | 8.8 | 27 | NO | NO |
CVE-2021-34342MEDIUM Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak. | Mar 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-34341MEDIUM Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service. | Mar 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-34339MEDIUM Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service. | Mar 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-34338MEDIUM Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service. | Mar 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-34340MEDIUM Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service | Mar 10, 2022 | 6.5 | 21 | NO | NO |
CVE-2017-11705MEDIUM A memory leak was found in the function parseSWF_SHAPEWITHSTYLE in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file. | Jul 28, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-11733MEDIUM A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a d | Jul 29, 2017 | 5.5 | 20 | NO | NO |
CVE-2017-11734MEDIUM A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted f | Jul 29, 2017 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ming
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.4.8 | 17 | 6.4 | 1.1% | 0 | 0 |