Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2021-3622

Disclosure Date: December 23, 2021 (last updated October 07, 2023)
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-3504

Disclosure Date: May 11, 2021 (last updated November 08, 2023)
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2014-9273

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.
0
Attacker Value
Unknown

CVE-2007-1954

Disclosure Date: April 11, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.
0
Attacker Value
Unknown

CVE-2005-2891

Disclosure Date: September 14, 2005 (last updated February 22, 2025)
WebArchiveX.dll 5.5.0.76 installed before September 6th, 2005 is marked safe for scripting by default, which allows remote attackers to read or write to arbitrary files via the (1) MakeArchive or (2) MakeArchiveStr methods.
0