7-Zip records
37 published records for vendor 7-zip.
Researcher profile
- Entered KEV
- 1 · 2.7%
- Weaponized
- 1 · 2.7%
- Pre-auth RCE
- 3
- With a fix record
- 86.5%
- Median publish → KEV
- 12 days
Recurring classes
- CWE-125 Out-of-bounds Read7
- CWE-787 Out-of-bounds Write4
- CWE-122 Heap-based Buffer Overflow3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
78This week | CVE-2025-0411Weaponized | 7-Zip Mark-of-the-Web Bypass Vulnerability7-zip · 7-zip · CWE-693 | High7.0 | KEV | 67.1% | Jan 25, 2025 |
48Plan | CVE-2023-31102No exploit | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.7-zip · 7-zip · CWE-191 | High7.8 | — | 57.1% | Nov 3, 2023 |
41Plan | CVE-2008-6536No exploit | Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit7-zip · 7-zip | Critical10.0 | — | 2.8% | Mar 29, 2009 |
39Monitor | CVE-2025-11001Proof of concept | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability7-zip · 7-zip · CWE-22 | High7.8 | — | 27.0% | Nov 19, 2025 |
38Monitor | CVE-2024-11477Proof of concept | 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability7-zip · 7-zip · CWE-191 | High7.8 | — | 22.6% | Nov 22, 2024 |
38Monitor | CVE-2016-2335No exploit | The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denialopensuse · opensuse · CWE-119 | High8.8 | — | 9.8% | Jun 7, 2016 |
35Monitor | CVE-2016-2334Proof of concept | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to7-zip · 7-zip · CWE-119 | High7.8 | — | 14.7% | Dec 13, 2016 |
35Monitor | CVE-2023-40481No exploit | 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability7-zip · 7-zip · CWE-787 | High7.8 | — | 13.9% | May 2, 2024 |
35Monitor | CVE-2026-48095Proof of concept | GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation7-zip · 7-zip · CWE-190 | High8.8 | — | 0.6% | Jun 5, 2026 |
35Monitor | CVE-2018-10172No exploit | 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor7-zip · 7-zip · CWE-269 | High8.8 | — | 0.4% | Apr 16, 2018 |
33Monitor | CVE-2023-52168No exploit | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite CWE-122 | High8.4 | — | 0.3% | Jul 3, 2024 |
32Monitor | CVE-2016-9296No exploit | A null pointer dereference bug affects the 16.02 and many old versions of p7zip.7-zip · p7zip · CWE-476 | High7.5 | — | 7.0% | Nov 11, 2016 |
32Monitor | CVE-2017-17969No exploit | Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c7-zip · 7-zip · CWE-787 | High7.8 | — | 4.9% | Jan 30, 2018 |
32Monitor | CVE-2018-10115No exploit | Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a7-zip · 7-zip · CWE-665 | High7.8 | — | 4.6% | May 2, 2018 |
32Monitor | CVE-2018-5996No exploit | Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c7-zip · 7-zip · CWE-119 | High7.8 | — | 2.9% | Jan 31, 2018 |
32Monitor | CVE-2016-7804No exploit | Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL7-zip · 7-zip · CWE-426 | High7.8 | — | 1.8% | May 22, 2017 |
32Monitor | CVE-2023-52169No exploit | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the iCWE-125 | High8.2 | — | 1.0% | Jul 3, 2024 |
32Monitor | CVE-2026-48092No exploit | 7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)7-zip · 7-zip · CWE-125 | High8.1 | — | 0.5% | Jun 5, 2026 |
31Monitor | CVE-2022-29072Proof of concept | 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C7-zip · 7-zip · CWE-787 | High7.8 | — | 1.5% | Apr 15, 2022 |
31Monitor | CVE-2026-14266Proof of concept | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability7-zip · 7-zip · CWE-122 | High7.8 | — | 0.7% | Jul 29, 2026 |
31Monitor | CVE-2025-11002No exploit | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability7-zip · 7-zip · CWE-22 | High7.8 | — | 0.5% | Jan 23, 2026 |
31Monitor | CVE-2022-47069No exploit | p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7-zip · p7zip · CWE-787 | High7.8 | — | 0.3% | Aug 22, 2023 |
29Monitor | CVE-2007-4725Proof of concept | Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u7-zip · 7-zip · CWE-400 | Medium6.8 | — | 5.6% | Sep 5, 2007 |
28Monitor | CVE-2026-48111No exploit | GHSL-2026-121 7-Zip UEFI DEPEX OOB Read7-zip · 7-zip · CWE-125 | High7.1 | — | 0.3% | Jun 5, 2026 |
28Monitor | CVE-2026-48103No exploit | GHSL-2026-119 7-Zip WIM SecurityId OOB read7-zip · 7-zip · CWE-125 | High7.1 | — | 0.3% | Jun 5, 2026 |
- CVE-2025-041178This week
7-Zip Mark-of-the-Web Bypass Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 67%7-zip · 7-zipJan 25, 2025
- CVE-2023-3110248Plan
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
HighCVSS 7.8No exploitEPSS 57%7-zip · 7-zipNov 3, 2023
- CVE-2008-653641Plan
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit
CriticalCVSS 10.0No exploitEPSS 3%7-zip · 7-zipMar 29, 2009
- CVE-2025-1100139Monitor
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
HighCVSS 7.8Proof of conceptEPSS 27%7-zip · 7-zipNov 19, 2025
- CVE-2024-1147738Monitor
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability
HighCVSS 7.8Proof of conceptEPSS 23%7-zip · 7-zipNov 22, 2024
- CVE-2016-233538Monitor
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial
HighCVSS 8.8No exploitEPSS 10%opensuse · opensuseJun 7, 2016
- CVE-2016-233435Monitor
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to
HighCVSS 7.8Proof of conceptEPSS 15%7-zip · 7-zipDec 13, 2016
- CVE-2023-4048135Monitor
7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 14%7-zip · 7-zipMay 2, 2024
- CVE-2026-4809535Monitor
GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
HighCVSS 8.8Proof of conceptEPSS 1%7-zip · 7-zipJun 5, 2026
- CVE-2018-1017235Monitor
7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor
HighCVSS 8.8No exploitEPSS 0%7-zip · 7-zipApr 16, 2018
- CVE-2023-5216833Monitor
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite
HighCVSS 8.4No exploitEPSS 0%Jul 3, 2024
- CVE-2016-929632Monitor
A null pointer dereference bug affects the 16.02 and many old versions of p7zip.
HighCVSS 7.5No exploitEPSS 7%7-zip · p7zipNov 11, 2016
- CVE-2017-1796932Monitor
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c
HighCVSS 7.8No exploitEPSS 5%7-zip · 7-zipJan 30, 2018
- CVE-2018-1011532Monitor
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a
HighCVSS 7.8No exploitEPSS 5%7-zip · 7-zipMay 2, 2018
- CVE-2018-599632Monitor
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c
HighCVSS 7.8No exploitEPSS 3%7-zip · 7-zipJan 31, 2018
- CVE-2016-780432Monitor
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL
HighCVSS 7.8No exploitEPSS 2%7-zip · 7-zipMay 22, 2017
- CVE-2023-5216932Monitor
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the i
HighCVSS 8.2No exploitEPSS 1%Jul 3, 2024
- CVE-2026-4809232Monitor
7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)
HighCVSS 8.1No exploitEPSS 0%7-zip · 7-zipJun 5, 2026
- CVE-2022-2907231Monitor
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C
HighCVSS 7.8Proof of conceptEPSS 2%7-zip · 7-zipApr 15, 2022
- CVE-2026-1426631Monitor
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 7.8Proof of conceptEPSS 1%7-zip · 7-zipJul 29, 2026
- CVE-2025-1100231Monitor
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 1%7-zip · 7-zipJan 23, 2026
- CVE-2022-4706931Monitor
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/
HighCVSS 7.8No exploitEPSS 0%7-zip · p7zipAug 22, 2023
- CVE-2007-472529Monitor
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u
MediumCVSS 6.8Proof of conceptEPSS 6%7-zip · 7-zipSep 5, 2007
- CVE-2026-4811128Monitor
GHSL-2026-121 7-Zip UEFI DEPEX OOB Read
HighCVSS 7.1No exploitEPSS 0%7-zip · 7-zipJun 5, 2026
- CVE-2026-4810328Monitor
GHSL-2026-119 7-Zip WIM SecurityId OOB read
HighCVSS 7.1No exploitEPSS 0%7-zip · 7-zipJun 5, 2026