Записи libarchive
76 опубликованных записей вендора libarchive.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 93,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read23
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-476 NULL Pointer Dereference9
- CWE-190 Integer Overflow or Wraparound8
- CWE-20 Improper Input Validation5
- CWE-416 Use After Free3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
76 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
56В плане | CVE-2024-26256Эксплойта нет | Libarchive Remote Code Execution Vulnerabilitylibarchive · libarchive · CWE-122 | Высокая7,8 | — | 84,8 % | 9 апр. 2024 г. |
40В плане | CVE-2022-36227Эксплойта нет | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if thlibarchive · libarchive · CWE-476 | Критическая9,8 | — | 2,4 % | 21 нояб. 2022 г. |
38Наблюдать | CVE-2016-1541Эксплойта нет | Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remolibarchive · libarchive · CWE-20 | Высокая8,8 | — | 10,3 % | 7 мая 2016 г. |
36Наблюдать | CVE-2016-6250Эксплойта нет | Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) olibarchive · libarchive · CWE-190 | Высокая8,6 | — | 6,3 % | 21 сент. 2016 г. |
36Наблюдать | CVE-2018-1000877Эксплойта нет | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerablibarchive · libarchive · CWE-415 | Высокая8,8 | — | 4,6 % | 20 дек. 2018 г. |
36Наблюдать | CVE-2018-1000878Эксплойта нет | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnelibarchive · libarchive · CWE-416 | Высокая8,8 | — | 4,4 % | 20 дек. 2018 г. |
36Наблюдать | CVE-2020-9308Эксплойта нет | archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a libarchive · libarchive · CWE-787 | Высокая8,8 | — | 2,3 % | 20 февр. 2020 г. |
36Наблюдать | CVE-2024-37407Эксплойта нет | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.libarchive · libarchive · CWE-125 | Критическая9,1 | — | 1,0 % | 8 июн. 2024 г. |
34Наблюдать | CVE-2015-8921Эксплойта нет | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-boundlibarchive · libarchive · CWE-125 | Высокая7,5 | — | 12,0 % | 20 сент. 2016 г. |
32Наблюдать | CVE-2016-8687Эксплойта нет | Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of servlibarchive · libarchive · CWE-119 | Высокая7,5 | — | 5,3 % | 15 февр. 2017 г. |
32Наблюдать | CVE-2016-4300Эксплойта нет | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackerlibarchive · libarchive · CWE-190 | Высокая7,8 | — | 4,9 % | 21 сент. 2016 г. |
32Наблюдать | CVE-2016-4302Эксплойта нет | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackelibarchive · libarchive · CWE-119 | Высокая7,8 | — | 4,8 % | 21 сент. 2016 г. |
32Наблюдать | CVE-2016-4301Эксплойта нет | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attlibarchive · libarchive · CWE-119 | Высокая7,8 | — | 3,7 % | 21 сент. 2016 г. |
32Наблюдать | CVE-2015-8931Эксплойта нет | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive blibarchive · libarchive · CWE-190 | Высокая7,8 | — | 2,1 % | 20 сент. 2016 г. |
31Наблюдать | CVE-2016-4809Эксплойта нет | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers tlibarchive · libarchive · CWE-20 | Высокая7,5 | — | 4,8 % | 21 сент. 2016 г. |
31Наблюдать | CVE-2016-5418Эксплойта нет | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attalibarchive · libarchive · CWE-19 | Высокая7,5 | — | 4,7 % | 21 сент. 2016 г. |
31Наблюдать | CVE-2015-8919Эксплойта нет | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause libarchive · libarchive · CWE-119 | Высокая7,5 | — | 4,5 % | 20 сент. 2016 г. |
31Наблюдать | CVE-2017-5601Эксплойта нет | An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to triggerlibarchive · libarchive · CWE-125 | Высокая7,5 | — | 4,5 % | 27 янв. 2017 г. |
31Наблюдать | CVE-2015-8917Эксплойта нет | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid clibarchive · libarchive · CWE-476 | Высокая7,5 | — | 4,3 % | 20 сент. 2016 г. |
31Наблюдать | CVE-2015-8930Эксплойта нет | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is alibarchive · libarchive · CWE-20 | Высокая7,5 | — | 4,3 % | 20 сент. 2016 г. |
31Наблюдать | CVE-2019-18408Эксплойта нет | archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_libarchive · libarchive · CWE-416 | Высокая7,5 | — | 4,0 % | 24 окт. 2019 г. |
31Наблюдать | CVE-2015-8918Эксплойта нет | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (craslibarchive · libarchive · CWE-119 | Высокая7,5 | — | 3,8 % | 20 сент. 2016 г. |
31Наблюдать | CVE-2017-14502Эксплойта нет | read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leadlibarchive · libarchive · CWE-125 | Высокая7,5 | — | 3,4 % | 17 сент. 2017 г. |
31Наблюдать | CVE-2016-8689Эксплойта нет | The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (outlibarchive · libarchive · CWE-125 | Высокая7,5 | — | 3,3 % | 15 февр. 2017 г. |
31Наблюдать | CVE-2024-48958Эксплойта нет | execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file libarchive · libarchive · CWE-125 | Высокая7,8 | — | 0,6 % | 9 окт. 2024 г. |
- CVE-2024-2625656В плане
Libarchive Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 85 %libarchive · libarchive9 апр. 2024 г.
- CVE-2022-3622740В плане
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libarchive · libarchive21 нояб. 2022 г.
- CVE-2016-154138Наблюдать
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remo
ВысокаяCVSS 8,8Эксплойта нетEPSS 10 %libarchive · libarchive7 мая 2016 г.
- CVE-2016-625036Наблюдать
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) o
ВысокаяCVSS 8,6Эксплойта нетEPSS 6 %libarchive · libarchive21 сент. 2016 г.
- CVE-2018-100087736Наблюдать
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerab
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %libarchive · libarchive20 дек. 2018 г.
- CVE-2018-100087836Наблюдать
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulne
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %libarchive · libarchive20 дек. 2018 г.
- CVE-2020-930836Наблюдать
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %libarchive · libarchive20 февр. 2020 г.
- CVE-2024-3740736Наблюдать
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %libarchive · libarchive8 июн. 2024 г.
- CVE-2015-892134Наблюдать
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bound
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %libarchive · libarchive20 сент. 2016 г.
- CVE-2016-868732Наблюдать
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of serv
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %libarchive · libarchive15 февр. 2017 г.
- CVE-2016-430032Наблюдать
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attacker
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %libarchive · libarchive21 сент. 2016 г.
- CVE-2016-430232Наблюдать
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attacke
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %libarchive · libarchive21 сент. 2016 г.
- CVE-2016-430132Наблюдать
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote att
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %libarchive · libarchive21 сент. 2016 г.
- CVE-2015-893132Наблюдать
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive b
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %libarchive · libarchive20 сент. 2016 г.
- CVE-2016-480931Наблюдать
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %libarchive · libarchive21 сент. 2016 г.
- CVE-2016-541831Наблюдать
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote atta
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %libarchive · libarchive21 сент. 2016 г.
- CVE-2015-891931Наблюдать
The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %libarchive · libarchive20 сент. 2016 г.
- CVE-2017-560131Наблюдать
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %libarchive · libarchive27 янв. 2017 г.
- CVE-2015-891731Наблюдать
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid c
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %libarchive · libarchive20 сент. 2016 г.
- CVE-2015-893031Наблюдать
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %libarchive · libarchive20 сент. 2016 г.
- CVE-2019-1840831Наблюдать
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %libarchive · libarchive24 окт. 2019 г.
- CVE-2015-891831Наблюдать
The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (cras
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %libarchive · libarchive20 сент. 2016 г.
- CVE-2017-1450231Наблюдать
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, lead
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libarchive · libarchive17 сент. 2017 г.
- CVE-2016-868931Наблюдать
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libarchive · libarchive15 февр. 2017 г.
- CVE-2024-4895831Наблюдать
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %libarchive · libarchive9 окт. 2024 г.