CVE-2024-28458: Swftools

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

Affected products

Published 2024-04-11. Last modified 2026-06-17.