CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp. NOTE: the Supplier has found that this is not a buff...Show more |
27 Zip Debian37 Zip Debian LinuxP7zipJan 10, 2025 Jan 31, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of se...Show more |
27 Zip Debian37 Zip Debian LinuxP7zipJan 10, 2025 Jan 30, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary...Show more |
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/...Show more |
37 Zip FedoraprojectOracle3Fedora P7zipSolarisMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive. |