CVE-2023-37644: Swftools

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.

Affected products

Published 2024-01-11. Last modified 2026-06-17.