Skip to content
Noroxi

libarchive records

76 published records for vendor libarchive.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
93.4%
Median publish → KEV
No record has entered KEV

All records

76 records
  • Libarchive Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 85%

    libarchive · libarchiveApr 9, 2024

  • In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th

    CriticalCVSS 9.8No exploitEPSS 2%

    libarchive · libarchiveNov 21, 2022

  • CVE-2016-1541
    38Monitor

    Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remo

    HighCVSS 8.8No exploitEPSS 10%

    libarchive · libarchiveMay 7, 2016

  • CVE-2016-6250
    36Monitor

    Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) o

    HighCVSS 8.6No exploitEPSS 6%

    libarchive · libarchiveSep 21, 2016

  • libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerab

    HighCVSS 8.8No exploitEPSS 5%

    libarchive · libarchiveDec 20, 2018

  • libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulne

    HighCVSS 8.8No exploitEPSS 4%

    libarchive · libarchiveDec 20, 2018

  • CVE-2020-9308
    36Monitor

    archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a

    HighCVSS 8.8No exploitEPSS 2%

    libarchive · libarchiveFeb 20, 2020

  • Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.

    CriticalCVSS 9.1No exploitEPSS 1%

    libarchive · libarchiveJun 8, 2024

  • CVE-2015-8921
    34Monitor

    The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bound

    HighCVSS 7.5No exploitEPSS 12%

    libarchive · libarchiveSep 20, 2016

  • CVE-2016-8687
    32Monitor

    Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of serv

    HighCVSS 7.5No exploitEPSS 5%

    libarchive · libarchiveFeb 15, 2017

  • CVE-2016-4300
    32Monitor

    Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attacker

    HighCVSS 7.8No exploitEPSS 5%

    libarchive · libarchiveSep 21, 2016

  • CVE-2016-4302
    32Monitor

    Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attacke

    HighCVSS 7.8No exploitEPSS 5%

    libarchive · libarchiveSep 21, 2016

  • CVE-2016-4301
    32Monitor

    Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote att

    HighCVSS 7.8No exploitEPSS 4%

    libarchive · libarchiveSep 21, 2016

  • CVE-2015-8931
    32Monitor

    Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive b

    HighCVSS 7.8No exploitEPSS 2%

    libarchive · libarchiveSep 20, 2016

  • CVE-2016-4809
    31Monitor

    The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers t

    HighCVSS 7.5No exploitEPSS 5%

    libarchive · libarchiveSep 21, 2016

  • CVE-2016-5418
    31Monitor

    The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote atta

    HighCVSS 7.5No exploitEPSS 5%

    libarchive · libarchiveSep 21, 2016

  • CVE-2015-8919
    31Monitor

    The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause

    HighCVSS 7.5No exploitEPSS 5%

    libarchive · libarchiveSep 20, 2016

  • CVE-2017-5601
    31Monitor

    An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger

    HighCVSS 7.5No exploitEPSS 5%

    libarchive · libarchiveJan 27, 2017

  • CVE-2015-8917
    31Monitor

    bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid c

    HighCVSS 7.5No exploitEPSS 4%

    libarchive · libarchiveSep 20, 2016

  • CVE-2015-8930
    31Monitor

    bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a

    HighCVSS 7.5No exploitEPSS 4%

    libarchive · libarchiveSep 20, 2016

  • archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_

    HighCVSS 7.5No exploitEPSS 4%

    libarchive · libarchiveOct 24, 2019

  • CVE-2015-8918
    31Monitor

    The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (cras

    HighCVSS 7.5No exploitEPSS 4%

    libarchive · libarchiveSep 20, 2016

  • read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, lead

    HighCVSS 7.5No exploitEPSS 3%

    libarchive · libarchiveSep 17, 2017

  • CVE-2016-8689
    31Monitor

    The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out

    HighCVSS 7.5No exploitEPSS 3%

    libarchive · libarchiveFeb 15, 2017

  • execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file

    HighCVSS 7.8No exploitEPSS 1%

    libarchive · libarchiveOct 9, 2024