
Cloud Vulnerability DB
A community-led vulnerabilities database
A heap-buffer-overflow vulnerability was discovered in swftools through version 20201222. The vulnerability exists in the function handleEditText() located in swfdump.c. This issue was assigned CVE-2021-42195 and was publicly disclosed on June 2, 2022 (NVD).
The vulnerability is classified as a heap-based buffer overflow vulnerability in the handleEditText() function of swfdump.c. The CVSS v3.1 base score is 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The issue occurs when reading beyond the bounds of an allocated memory region, specifically one byte past a 51-byte allocated region (GitHub Issue).
The vulnerability allows an attacker to cause code execution on the target system. The high CVSS score indicates potential severe impacts on confidentiality, integrity, and availability of the affected system (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."