← Vulnerability feed

Vulnerability record · CVE-2019-7581 · published 7 February 2019

CVE-2019-7581: Libming allocation without limits vulnerability

LLibming · Libming

The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876.

8.8 CVSS 3.0 High EPSS 2.1% · top 18.8% CWE-770 · Allocation without limits
8.8CVSS 3.0 base score, v2 6.8
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/libming/libming/issues/173 ExploitPatchThird Party Advisory
https://github.com/libming/libming/issues/173 ExploitPatchThird Party Advisory

Track CVE-2019-7581 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-50628Libming classic buffer overflow vulnerabilityBuffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c comp…EPSS 1.3%9.1CVE-2020-11894Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.EPSS 1.7%9.1CVE-2020-11895Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.EPSS 1.7%9.1CVE-2019-16705Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.EPSS 1.7%8.8CVE-2023-36239Libming classic buffer overflow vulnerabilitylibming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.EPSS 0.70%8.8CVE-2023-31976Libming out-of-bounds write vulnerabilitylibming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c.EPSS 0.70%8.8CVE-2020-6628Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.EPSS 1.5%8.8CVE-2019-12981Libming improper input validation vulnerabilityMing (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2019-7581), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.