CVE-2025-26307
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-26307 is a denial-of-service vulnerability affecting the parseSWF_IMPORTASSETS2 function in libming v0.4.8's util/parser.c. The issue arises from a memory leak in this function, which can be exploited by attackers to cause excessive memory consumption. By providing a specially crafted SWF file, they can induce the software to allocate and leak memory, eventually leading to a system crash or unresponsiveness. This vulnerability poses a significant risk, particularly in environments where users are exposed to untrusted SWF files, and requires immediate patching to prevent potential disruptions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.