← Back

Lhaplus

lhaplus

Vendor: Lhaplus • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lhaplus
1Lhaplus
May 6, 2026
Apr 15, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in Lhaplus before 1.70 allows remote attackers to execute arbitrary code via a crafted archive.
1Lhaplus
1Lhaplus
May 6, 2026
Apr 15, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.
1Lhaplus
1Lhaplus
Apr 29, 2026
Oct 19, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
1Lhaplus
1Lhaplus
Apr 29, 2026
Oct 18, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in Lhaplus before 1.58 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
1Lhaplus
1Lhaplus
Apr 23, 2026
Apr 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archive.
1Lhaplus
1Lhaplus
Apr 23, 2026
Nov 30, 2007
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Buffer overflow in Lhaplus 1.55 and earlier allows remote attackers to execute arbitrary code via a crafted LZH archive, a different vector than CVE-2007-5048.
1Lhaplus
1Lhaplus
Apr 23, 2026
Sep 24, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Lhaplus before 1.55 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.
1Lhaplus
1Lhaplus
Apr 16, 2026
Aug 9, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LZH archive with a long header, as specified by the extendedHeaderSize.