{"id":"CVE-2026-95125","title":"libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c","summary":"libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can cause a denial of service.","severity":"none","published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:33:42.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95125","references":[{"url":"https://github.com/libming/libming/issues/448","label":"cve@mitre.org"},{"url":"https://github.com/libming/libming/pull/450","label":"cve@mitre.org"},{"url":"https://github.com/libming/libming/pull/450/changes/2a255b0aae9d22461c4e49b0b83be2fa4be40277","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T14:47:16.356Z","slug":"CVE-2026-95125","body":"## Overview\n\nlibming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can cause a denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}