← Vulnerability feed

Vulnerability record · CVE-2023-36239 · published 22 June 2023

CVE-2023-36239: Libming classic buffer overflow vulnerability

LLibming · Libming

libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.

8.8 CVSS 3.1 High EPSS 0.70% · top 48.6% CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

libming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/libming/libming/issues/273 ExploitIssue TrackingThird Party Advisory
https://github.com/libming/libming/issues/273 ExploitIssue TrackingThird Party Advisory

Track CVE-2023-36239 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-50628Libming classic buffer overflow vulnerabilityBuffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c comp…EPSS 1.3%9.1CVE-2020-11894Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.EPSS 1.7%9.1CVE-2020-11895Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c.EPSS 1.7%9.1CVE-2019-16705Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.EPSS 1.7%8.8CVE-2023-31976Libming out-of-bounds write vulnerabilitylibming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c.EPSS 0.70%8.8CVE-2020-6628Libming out-of-bounds read vulnerabilityMing (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.EPSS 1.5%8.8CVE-2019-12981Libming improper input validation vulnerabilityMing (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.EPSS 1.3%8.8CVE-2019-7581Libming allocation without limits vulnerabilityThe parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf fil…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2023-36239), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.