libarchive records
76 published records for vendor libarchive.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 93.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read23
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-476 NULL Pointer Dereference9
- CWE-190 Integer Overflow or Wraparound8
- CWE-20 Improper Input Validation5
- CWE-416 Use After Free3
The weakness classes this vendor ships most often: where to look.
CWEAll records
76 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2024-26256No exploit | Libarchive Remote Code Execution Vulnerabilitylibarchive · libarchive · CWE-122 | High7.8 | — | 84.8% | Apr 9, 2024 |
40Plan | CVE-2022-36227No exploit | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if thlibarchive · libarchive · CWE-476 | Critical9.8 | — | 2.4% | Nov 21, 2022 |
38Monitor | CVE-2016-1541No exploit | Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remolibarchive · libarchive · CWE-20 | High8.8 | — | 10.3% | May 7, 2016 |
36Monitor | CVE-2016-6250No exploit | Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) olibarchive · libarchive · CWE-190 | High8.6 | — | 6.3% | Sep 21, 2016 |
36Monitor | CVE-2018-1000877No exploit | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerablibarchive · libarchive · CWE-415 | High8.8 | — | 4.6% | Dec 20, 2018 |
36Monitor | CVE-2018-1000878No exploit | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnelibarchive · libarchive · CWE-416 | High8.8 | — | 4.4% | Dec 20, 2018 |
36Monitor | CVE-2020-9308No exploit | archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a libarchive · libarchive · CWE-787 | High8.8 | — | 2.3% | Feb 20, 2020 |
36Monitor | CVE-2024-37407No exploit | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.libarchive · libarchive · CWE-125 | Critical9.1 | — | 1.0% | Jun 8, 2024 |
34Monitor | CVE-2015-8921No exploit | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-boundlibarchive · libarchive · CWE-125 | High7.5 | — | 12.0% | Sep 20, 2016 |
32Monitor | CVE-2016-8687No exploit | Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of servlibarchive · libarchive · CWE-119 | High7.5 | — | 5.3% | Feb 15, 2017 |
32Monitor | CVE-2016-4300No exploit | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackerlibarchive · libarchive · CWE-190 | High7.8 | — | 4.9% | Sep 21, 2016 |
32Monitor | CVE-2016-4302No exploit | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackelibarchive · libarchive · CWE-119 | High7.8 | — | 4.8% | Sep 21, 2016 |
32Monitor | CVE-2016-4301No exploit | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attlibarchive · libarchive · CWE-119 | High7.8 | — | 3.7% | Sep 21, 2016 |
32Monitor | CVE-2015-8931No exploit | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive blibarchive · libarchive · CWE-190 | High7.8 | — | 2.1% | Sep 20, 2016 |
31Monitor | CVE-2016-4809No exploit | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers tlibarchive · libarchive · CWE-20 | High7.5 | — | 4.8% | Sep 21, 2016 |
31Monitor | CVE-2016-5418No exploit | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attalibarchive · libarchive · CWE-19 | High7.5 | — | 4.7% | Sep 21, 2016 |
31Monitor | CVE-2015-8919No exploit | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause libarchive · libarchive · CWE-119 | High7.5 | — | 4.5% | Sep 20, 2016 |
31Monitor | CVE-2017-5601No exploit | An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to triggerlibarchive · libarchive · CWE-125 | High7.5 | — | 4.5% | Jan 27, 2017 |
31Monitor | CVE-2015-8917No exploit | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid clibarchive · libarchive · CWE-476 | High7.5 | — | 4.3% | Sep 20, 2016 |
31Monitor | CVE-2015-8930No exploit | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is alibarchive · libarchive · CWE-20 | High7.5 | — | 4.3% | Sep 20, 2016 |
31Monitor | CVE-2019-18408No exploit | archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_libarchive · libarchive · CWE-416 | High7.5 | — | 4.0% | Oct 24, 2019 |
31Monitor | CVE-2015-8918No exploit | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (craslibarchive · libarchive · CWE-119 | High7.5 | — | 3.8% | Sep 20, 2016 |
31Monitor | CVE-2017-14502No exploit | read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leadlibarchive · libarchive · CWE-125 | High7.5 | — | 3.4% | Sep 17, 2017 |
31Monitor | CVE-2016-8689No exploit | The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (outlibarchive · libarchive · CWE-125 | High7.5 | — | 3.3% | Feb 15, 2017 |
31Monitor | CVE-2024-48958No exploit | execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file libarchive · libarchive · CWE-125 | High7.8 | — | 0.6% | Oct 9, 2024 |
- CVE-2024-2625656Plan
Libarchive Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 85%libarchive · libarchiveApr 9, 2024
- CVE-2022-3622740Plan
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th
CriticalCVSS 9.8No exploitEPSS 2%libarchive · libarchiveNov 21, 2022
- CVE-2016-154138Monitor
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remo
HighCVSS 8.8No exploitEPSS 10%libarchive · libarchiveMay 7, 2016
- CVE-2016-625036Monitor
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) o
HighCVSS 8.6No exploitEPSS 6%libarchive · libarchiveSep 21, 2016
- CVE-2018-100087736Monitor
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerab
HighCVSS 8.8No exploitEPSS 5%libarchive · libarchiveDec 20, 2018
- CVE-2018-100087836Monitor
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulne
HighCVSS 8.8No exploitEPSS 4%libarchive · libarchiveDec 20, 2018
- CVE-2020-930836Monitor
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a
HighCVSS 8.8No exploitEPSS 2%libarchive · libarchiveFeb 20, 2020
- CVE-2024-3740736Monitor
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.
CriticalCVSS 9.1No exploitEPSS 1%libarchive · libarchiveJun 8, 2024
- CVE-2015-892134Monitor
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bound
HighCVSS 7.5No exploitEPSS 12%libarchive · libarchiveSep 20, 2016
- CVE-2016-868732Monitor
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of serv
HighCVSS 7.5No exploitEPSS 5%libarchive · libarchiveFeb 15, 2017
- CVE-2016-430032Monitor
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attacker
HighCVSS 7.8No exploitEPSS 5%libarchive · libarchiveSep 21, 2016
- CVE-2016-430232Monitor
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attacke
HighCVSS 7.8No exploitEPSS 5%libarchive · libarchiveSep 21, 2016
- CVE-2016-430132Monitor
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote att
HighCVSS 7.8No exploitEPSS 4%libarchive · libarchiveSep 21, 2016
- CVE-2015-893132Monitor
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive b
HighCVSS 7.8No exploitEPSS 2%libarchive · libarchiveSep 20, 2016
- CVE-2016-480931Monitor
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers t
HighCVSS 7.5No exploitEPSS 5%libarchive · libarchiveSep 21, 2016
- CVE-2016-541831Monitor
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote atta
HighCVSS 7.5No exploitEPSS 5%libarchive · libarchiveSep 21, 2016
- CVE-2015-891931Monitor
The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause
HighCVSS 7.5No exploitEPSS 5%libarchive · libarchiveSep 20, 2016
- CVE-2017-560131Monitor
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger
HighCVSS 7.5No exploitEPSS 5%libarchive · libarchiveJan 27, 2017
- CVE-2015-891731Monitor
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid c
HighCVSS 7.5No exploitEPSS 4%libarchive · libarchiveSep 20, 2016
- CVE-2015-893031Monitor
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a
HighCVSS 7.5No exploitEPSS 4%libarchive · libarchiveSep 20, 2016
- CVE-2019-1840831Monitor
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_
HighCVSS 7.5No exploitEPSS 4%libarchive · libarchiveOct 24, 2019
- CVE-2015-891831Monitor
The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (cras
HighCVSS 7.5No exploitEPSS 4%libarchive · libarchiveSep 20, 2016
- CVE-2017-1450231Monitor
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, lead
HighCVSS 7.5No exploitEPSS 3%libarchive · libarchiveSep 17, 2017
- CVE-2016-868931Monitor
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out
HighCVSS 7.5No exploitEPSS 3%libarchive · libarchiveFeb 15, 2017
- CVE-2024-4895831Monitor
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file
HighCVSS 7.8No exploitEPSS 1%libarchive · libarchiveOct 9, 2024