CVEs (76)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, relate...Show more |
3Canonical LibarchiveSuse5Libarchive Linux Enterprise DesktopLinux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive. |
3Canonical LibarchiveSuse5Libarchive Linux Enterprise DesktopLinux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. |
4Canonical LibarchiveNovell+1 more6Libarchive LinuxSuse Linux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to th...Show more |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. |
2Libarchive Novell4Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy." |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereferenc...Show more |
bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file. |
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP ar...Show more |
3Canonical LibarchiveOpensuse3Libarchive OpensuseUbuntu LinuxMay 6, 2026 Mar 15, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive. |
5Canonical FedoraprojectFreebsd+2 more5Fedora FreebsdLibarchive+2 moreApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of...Show more |