CVE-2017-7698: Swftools

High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.

A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf 3.02.

Affected products

  • Swftools Swftools: up to and including 0.9.2

Published 2017-05-10. Last modified 2026-06-17.