Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2025-0411

High priority
Not affected

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this...

2 affected packages

7zip, p7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Not affected Not affected Not in release
p7zip Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-11612

Medium priority
Vulnerable

7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library is required to...

2 affected packages

7zip, p7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Vulnerable Vulnerable Not in release
p7zip Not affected Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-11477

Medium priority
Needs evaluation

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is...

2 affected packages

7zip, p7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Not affected Not affected Not in release
p7zip Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-52169

Medium priority

Some fixes available 2 of 3

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a...

1 affected package

7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Fixed Fixed Not in release
Show less packages

CVE-2023-52168

Medium priority

Some fixes available 2 of 3

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9,...

1 affected package

7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Fixed Fixed Not in release
Show less packages

CVE-2023-40481

Medium priority
Needs evaluation

7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit...

1 affected package

7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Not affected Needs evaluation Not in release Ignored Ignored
Show less packages

CVE-2023-31102

Medium priority
Needs evaluation

Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

1 affected package

7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
7zip Not affected Needs evaluation Not in release Ignored Ignored
Show less packages

CVE-2022-47069

Medium priority
Needs evaluation

p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp.

1 affected package

p7zip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
p7zip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-10115

Medium priority
Needs evaluation

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a...

1 affected package

p7zip-rar

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
p7zip-rar Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2018-5996

Medium priority
Vulnerable

Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service...

1 affected package

p7zip-rar

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
p7zip-rar Not affected Not affected Not affected Not affected Vulnerable
Show less packages