Vulnerabilities
Vulnerable Software
7-Zip:  Security Vulnerabilities
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
CVSS Score
7.8
EPSS Score
0.172
Published
2016-12-13
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.
CVSS Score
7.5
EPSS Score
0.01
Published
2016-11-12
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.
CVSS Score
8.8
EPSS Score
0.018
Published
2016-06-07
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
CVSS Score
5.8
EPSS Score
0.021
Published
2015-01-21
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).
CVSS Score
10.0
EPSS Score
0.004
Published
2009-03-30
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.
CVSS Score
6.8
EPSS Score
0.165
Published
2007-09-05


Contact Us

Shodan ® - All rights reserved