Записи 7-Zip
37 опубликованных записей вендора 7-zip.
Профиль для исследователя
- Попали в KEV
- 1 · 2,7 %
- С эксплойтом
- 1 · 2,7 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 86,5 %
- Медиана: публикация → KEV
- 12 дн.
Повторяющиеся классы
- CWE-125 Out-of-bounds Read7
- CWE-787 Out-of-bounds Write4
- CWE-122 Heap-based Buffer Overflow3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
78На этой неделе | CVE-2025-0411Готовый эксплойт | 7-Zip Mark-of-the-Web Bypass Vulnerability7-zip · 7-zip · CWE-693 | Высокая7,0 | KEV | 67,1 % | 25 янв. 2025 г. |
48В плане | CVE-2023-31102Эксплойта нет | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.7-zip · 7-zip · CWE-191 | Высокая7,8 | — | 57,1 % | 3 нояб. 2023 г. |
41В плане | CVE-2008-6536Эксплойта нет | Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit7-zip · 7-zip | Критическая10,0 | — | 2,8 % | 29 мар. 2009 г. |
39Наблюдать | CVE-2025-11001Proof of concept | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability7-zip · 7-zip · CWE-22 | Высокая7,8 | — | 27,0 % | 19 нояб. 2025 г. |
38Наблюдать | CVE-2024-11477Proof of concept | 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability7-zip · 7-zip · CWE-191 | Высокая7,8 | — | 22,6 % | 22 нояб. 2024 г. |
38Наблюдать | CVE-2016-2335Эксплойта нет | The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denialopensuse · opensuse · CWE-119 | Высокая8,8 | — | 9,8 % | 7 июн. 2016 г. |
35Наблюдать | CVE-2016-2334Proof of concept | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to7-zip · 7-zip · CWE-119 | Высокая7,8 | — | 14,7 % | 13 дек. 2016 г. |
35Наблюдать | CVE-2023-40481Эксплойта нет | 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability7-zip · 7-zip · CWE-787 | Высокая7,8 | — | 13,9 % | 2 мая 2024 г. |
35Наблюдать | CVE-2026-48095Proof of concept | GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation7-zip · 7-zip · CWE-190 | Высокая8,8 | — | 0,6 % | 5 июн. 2026 г. |
35Наблюдать | CVE-2018-10172Эксплойта нет | 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor7-zip · 7-zip · CWE-269 | Высокая8,8 | — | 0,4 % | 16 апр. 2018 г. |
33Наблюдать | CVE-2023-52168Эксплойта нет | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite CWE-122 | Высокая8,4 | — | 0,3 % | 3 июл. 2024 г. |
32Наблюдать | CVE-2016-9296Эксплойта нет | A null pointer dereference bug affects the 16.02 and many old versions of p7zip.7-zip · p7zip · CWE-476 | Высокая7,5 | — | 7,0 % | 11 нояб. 2016 г. |
32Наблюдать | CVE-2017-17969Эксплойта нет | Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c7-zip · 7-zip · CWE-787 | Высокая7,8 | — | 4,9 % | 30 янв. 2018 г. |
32Наблюдать | CVE-2018-10115Эксплойта нет | Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a7-zip · 7-zip · CWE-665 | Высокая7,8 | — | 4,6 % | 2 мая 2018 г. |
32Наблюдать | CVE-2018-5996Эксплойта нет | Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c7-zip · 7-zip · CWE-119 | Высокая7,8 | — | 2,9 % | 31 янв. 2018 г. |
32Наблюдать | CVE-2016-7804Эксплойта нет | Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL7-zip · 7-zip · CWE-426 | Высокая7,8 | — | 1,8 % | 22 мая 2017 г. |
32Наблюдать | CVE-2023-52169Эксплойта нет | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the iCWE-125 | Высокая8,2 | — | 1,0 % | 3 июл. 2024 г. |
32Наблюдать | CVE-2026-48092Эксплойта нет | 7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)7-zip · 7-zip · CWE-125 | Высокая8,1 | — | 0,5 % | 5 июн. 2026 г. |
31Наблюдать | CVE-2022-29072Proof of concept | 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C7-zip · 7-zip · CWE-787 | Высокая7,8 | — | 1,5 % | 15 апр. 2022 г. |
31Наблюдать | CVE-2026-14266Proof of concept | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability7-zip · 7-zip · CWE-122 | Высокая7,8 | — | 0,7 % | 29 июл. 2026 г. |
31Наблюдать | CVE-2025-11002Эксплойта нет | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability7-zip · 7-zip · CWE-22 | Высокая7,8 | — | 0,5 % | 23 янв. 2026 г. |
31Наблюдать | CVE-2022-47069Эксплойта нет | p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7-zip · p7zip · CWE-787 | Высокая7,8 | — | 0,3 % | 22 авг. 2023 г. |
29Наблюдать | CVE-2007-4725Proof of concept | Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u7-zip · 7-zip · CWE-400 | Средняя6,8 | — | 5,6 % | 5 сент. 2007 г. |
28Наблюдать | CVE-2026-48111Эксплойта нет | GHSL-2026-121 7-Zip UEFI DEPEX OOB Read7-zip · 7-zip · CWE-125 | Высокая7,1 | — | 0,3 % | 5 июн. 2026 г. |
28Наблюдать | CVE-2026-48103Эксплойта нет | GHSL-2026-119 7-Zip WIM SecurityId OOB read7-zip · 7-zip · CWE-125 | Высокая7,1 | — | 0,3 % | 5 июн. 2026 г. |
- CVE-2025-041178На этой неделе
7-Zip Mark-of-the-Web Bypass Vulnerability
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 67 %7-zip · 7-zip25 янв. 2025 г.
- CVE-2023-3110248В плане
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
ВысокаяCVSS 7,8Эксплойта нетEPSS 57 %7-zip · 7-zip3 нояб. 2023 г.
- CVE-2008-653641В плане
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %7-zip · 7-zip29 мар. 2009 г.
- CVE-2025-1100139Наблюдать
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 27 %7-zip · 7-zip19 нояб. 2025 г.
- CVE-2024-1147738Наблюдать
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 23 %7-zip · 7-zip22 нояб. 2024 г.
- CVE-2016-233538Наблюдать
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial
ВысокаяCVSS 8,8Эксплойта нетEPSS 10 %opensuse · opensuse7 июн. 2016 г.
- CVE-2016-233435Наблюдать
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to
ВысокаяCVSS 7,8Proof of conceptEPSS 15 %7-zip · 7-zip13 дек. 2016 г.
- CVE-2023-4048135Наблюдать
7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 14 %7-zip · 7-zip2 мая 2024 г.
- CVE-2026-4809535Наблюдать
GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %7-zip · 7-zip5 июн. 2026 г.
- CVE-2018-1017235Наблюдать
7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %7-zip · 7-zip16 апр. 2018 г.
- CVE-2023-5216833Наблюдать
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %3 июл. 2024 г.
- CVE-2016-929632Наблюдать
A null pointer dereference bug affects the 16.02 and many old versions of p7zip.
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %7-zip · p7zip11 нояб. 2016 г.
- CVE-2017-1796932Наблюдать
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %7-zip · 7-zip30 янв. 2018 г.
- CVE-2018-1011532Наблюдать
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %7-zip · 7-zip2 мая 2018 г.
- CVE-2018-599632Наблюдать
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %7-zip · 7-zip31 янв. 2018 г.
- CVE-2016-780432Наблюдать
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %7-zip · 7-zip22 мая 2017 г.
- CVE-2023-5216932Наблюдать
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the i
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %3 июл. 2024 г.
- CVE-2026-4809232Наблюдать
7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %7-zip · 7-zip5 июн. 2026 г.
- CVE-2022-2907231Наблюдать
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %7-zip · 7-zip15 апр. 2022 г.
- CVE-2026-1426631Наблюдать
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %7-zip · 7-zip29 июл. 2026 г.
- CVE-2025-1100231Наблюдать
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %7-zip · 7-zip23 янв. 2026 г.
- CVE-2022-4706931Наблюдать
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %7-zip · p7zip22 авг. 2023 г.
- CVE-2007-472529Наблюдать
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u
СредняяCVSS 6,8Proof of conceptEPSS 6 %7-zip · 7-zip5 сент. 2007 г.
- CVE-2026-4811128Наблюдать
GHSL-2026-121 7-Zip UEFI DEPEX OOB Read
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %7-zip · 7-zip5 июн. 2026 г.
- CVE-2026-4810328Наблюдать
GHSL-2026-119 7-Zip WIM SecurityId OOB read
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %7-zip · 7-zip5 июн. 2026 г.