Skip to content
Noroxi

7-Zip records

37 published records for vendor 7-zip.

All records

37 records
  • CVE-2025-0411
    78This week

    7-Zip Mark-of-the-Web Bypass Vulnerability

    HighCVSS 7.0KEVWeaponizedEPSS 67%

    7-zip · 7-zipJan 25, 2025

  • Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

    HighCVSS 7.8No exploitEPSS 57%

    7-zip · 7-zipNov 3, 2023

  • Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit

    CriticalCVSS 10.0No exploitEPSS 3%

    7-zip · 7-zipMar 29, 2009

  • 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability

    HighCVSS 7.8Proof of conceptEPSS 27%

    7-zip · 7-zipNov 19, 2025

  • 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability

    HighCVSS 7.8Proof of conceptEPSS 23%

    7-zip · 7-zipNov 22, 2024

  • CVE-2016-2335
    38Monitor

    The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial

    HighCVSS 8.8No exploitEPSS 10%

    opensuse · opensuseJun 7, 2016

  • CVE-2016-2334
    35Monitor

    Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to

    HighCVSS 7.8Proof of conceptEPSS 15%

    7-zip · 7-zipDec 13, 2016

  • 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 14%

    7-zip · 7-zipMay 2, 2024

  • GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation

    HighCVSS 8.8Proof of conceptEPSS 1%

    7-zip · 7-zipJun 5, 2026

  • 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor

    HighCVSS 8.8No exploitEPSS 0%

    7-zip · 7-zipApr 16, 2018

  • The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite

    HighCVSS 8.4No exploitEPSS 0%

    Jul 3, 2024

  • CVE-2016-9296
    32Monitor

    A null pointer dereference bug affects the 16.02 and many old versions of p7zip.

    HighCVSS 7.5No exploitEPSS 7%

    7-zip · p7zipNov 11, 2016

  • Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c

    HighCVSS 7.8No exploitEPSS 5%

    7-zip · 7-zipJan 30, 2018

  • Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a

    HighCVSS 7.8No exploitEPSS 5%

    7-zip · 7-zipMay 2, 2018

  • CVE-2018-5996
    32Monitor

    Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c

    HighCVSS 7.8No exploitEPSS 3%

    7-zip · 7-zipJan 31, 2018

  • CVE-2016-7804
    32Monitor

    Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL

    HighCVSS 7.8No exploitEPSS 2%

    7-zip · 7-zipMay 22, 2017

  • The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the i

    HighCVSS 8.2No exploitEPSS 1%

    Jul 3, 2024

  • 7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)

    HighCVSS 8.1No exploitEPSS 0%

    7-zip · 7-zipJun 5, 2026

  • 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C

    HighCVSS 7.8Proof of conceptEPSS 2%

    7-zip · 7-zipApr 15, 2022

  • 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.8Proof of conceptEPSS 1%

    7-zip · 7-zipJul 29, 2026

  • 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 1%

    7-zip · 7-zipJan 23, 2026

  • p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/

    HighCVSS 7.8No exploitEPSS 0%

    7-zip · p7zipAug 22, 2023

  • CVE-2007-4725
    29Monitor

    Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u

    MediumCVSS 6.8Proof of conceptEPSS 6%

    7-zip · 7-zipSep 5, 2007

  • GHSL-2026-121 7-Zip UEFI DEPEX OOB Read

    HighCVSS 7.1No exploitEPSS 0%

    7-zip · 7-zipJun 5, 2026

  • GHSL-2026-119 7-Zip WIM SecurityId OOB read

    HighCVSS 7.1No exploitEPSS 0%

    7-zip · 7-zipJun 5, 2026