Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2017-17969

Disclosure Date: January 30, 2018 (last updated November 26, 2024)
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
0
Attacker Value
Unknown

CVE-2016-7804

Disclosure Date: May 22, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2016-2334

Disclosure Date: December 13, 2016 (last updated November 08, 2023)
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
0
Attacker Value
Unknown

CVE-2016-9296

Disclosure Date: November 12, 2016 (last updated November 25, 2024)
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
0
Attacker Value
Unknown

CVE-2016-2335

Disclosure Date: June 07, 2016 (last updated November 08, 2023)
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.
0
Attacker Value
Unknown

CVE-2015-1038

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
0
Attacker Value
Unknown

CVE-2008-6536

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).
0
Attacker Value
Unknown

CVE-2007-4725

Disclosure Date: September 05, 2007 (last updated October 04, 2023)
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.
0