Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Swftools

First CVE: Aug 17, 2010Active for: 16 yearsTotal CVEs: 126
21.7
VTI Score
Low

Swftools is a compact utility suite for parsing, converting, and manipulating SWF (Flash) files, a format that sees limited but specialized use in legacy media workflows and embedded contexts. Despite a narrow product scope, the toolkit occupies a notable position in vulnerability research due to its role in processing untrusted binary formats, and its disclosures span a broad range of memory-safety classes that reflect the complexity of SWF parsing. The recurring vulnerability pattern centers on out-of-bounds access, NULL-pointer dereference, and use-after-free conditions within buffer-handling operations—flaws endemic to C-based parsers processing structurally complex binary input without modern memory protections. Defenders deploying swftools in automated conversion or media-processing pipelines should prioritize updates and apply input validation, particularly where the tool processes untrusted or user-supplied SWF files; live severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
126
Total CVEs
More Total CVEs than 99% of tracked vendors
15.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Swftools over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 17, 2010
15 years ago
Most Recent CVE
Jun 19, 2025
400 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (126 CVEs).

126 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-40009CRITICAL
SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.
Sep 20, 20229.832NONO
CVE-2022-40008CRITICAL
SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
Sep 20, 20229.831NONO
CVE-2017-8400HIGH
In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755. This issue can be triggered by a malformed PNG file that is mishandled
May 1, 20178.828NONO
CVE-2017-11101HIGH
When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/modules/swftools.c.
Jul 7, 20178.827NONO
CVE-2017-9927HIGH
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to a "Rea
Jul 5, 20178.827NONO
CVE-2017-9925HIGH
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV
Jul 5, 20178.827NONO
CVE-2017-9924HIGH
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV
Jul 5, 20178.827NONO
CVE-2010-1516HIGH
Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a craf
Aug 17, 20109.327NONO
CVE-2017-11100HIGH
When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in lib/rxfswf.c.
Jul 7, 20178.826NONO
CVE-2017-11098HIGH
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.
Jul 7, 20178.826NONO
View all 126 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products126 CVEs
61%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local104 (82.5%)
Network21 (16.7%)
Unknown1 (0.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low125 (99.2%)
High0 (0.0%)
Unknown1 (0.8%)
User Interaction
None8 (6.3%)
Unknown1 (0.8%)
Required117 (92.9%)
Privileges Required
Low3 (2.4%)
High0 (0.0%)
None122 (96.8%)
Unknown1 (0.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (126 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Swftools.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Swftools — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Swftools's Products

View all 2 CNAs →

Top CWEs