7-Zip kayıtları
7-zip üreticisine ait 37 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,7
- Silahlaştırılmış
- 1 · %2,7
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %86,5
- Yayından KEV’e ortanca
- 12 gün
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read7
- CWE-787 Out-of-bounds Write4
- CWE-122 Heap-based Buffer Overflow3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
37 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
78Bu hafta | CVE-2025-0411Silahlaştırılmış | 7-Zip Mark-of-the-Web Bypass Vulnerability7-zip · 7-zip · CWE-693 | Yüksek7,0 | KEV | %67,1 | 25 Oca 2025 |
48Planlayın | CVE-2023-31102İstismar yok | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.7-zip · 7-zip · CWE-191 | Yüksek7,8 | — | %57,1 | 3 Kas 2023 |
41Planlayın | CVE-2008-6536İstismar yok | Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit7-zip · 7-zip | Kritik10,0 | — | %2,8 | 29 Mar 2009 |
39İzleyin | CVE-2025-11001Kavram kanıtı | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability7-zip · 7-zip · CWE-22 | Yüksek7,8 | — | %27,0 | 19 Kas 2025 |
38İzleyin | CVE-2024-11477Kavram kanıtı | 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability7-zip · 7-zip · CWE-191 | Yüksek7,8 | — | %22,6 | 22 Kas 2024 |
38İzleyin | CVE-2016-2335İstismar yok | The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denialopensuse · opensuse · CWE-119 | Yüksek8,8 | — | %9,8 | 7 Haz 2016 |
35İzleyin | CVE-2016-2334Kavram kanıtı | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to7-zip · 7-zip · CWE-119 | Yüksek7,8 | — | %14,7 | 13 Ara 2016 |
35İzleyin | CVE-2023-40481İstismar yok | 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability7-zip · 7-zip · CWE-787 | Yüksek7,8 | — | %13,9 | 2 May 2024 |
35İzleyin | CVE-2026-48095Kavram kanıtı | GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation7-zip · 7-zip · CWE-190 | Yüksek8,8 | — | %0,6 | 5 Haz 2026 |
35İzleyin | CVE-2018-10172İstismar yok | 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor7-zip · 7-zip · CWE-269 | Yüksek8,8 | — | %0,4 | 16 Nis 2018 |
33İzleyin | CVE-2023-52168İstismar yok | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite CWE-122 | Yüksek8,4 | — | %0,3 | 3 Tem 2024 |
32İzleyin | CVE-2016-9296İstismar yok | A null pointer dereference bug affects the 16.02 and many old versions of p7zip.7-zip · p7zip · CWE-476 | Yüksek7,5 | — | %7,0 | 11 Kas 2016 |
32İzleyin | CVE-2017-17969İstismar yok | Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c7-zip · 7-zip · CWE-787 | Yüksek7,8 | — | %4,9 | 30 Oca 2018 |
32İzleyin | CVE-2018-10115İstismar yok | Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a7-zip · 7-zip · CWE-665 | Yüksek7,8 | — | %4,6 | 2 May 2018 |
32İzleyin | CVE-2018-5996İstismar yok | Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c7-zip · 7-zip · CWE-119 | Yüksek7,8 | — | %2,9 | 31 Oca 2018 |
32İzleyin | CVE-2016-7804İstismar yok | Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL7-zip · 7-zip · CWE-426 | Yüksek7,8 | — | %1,8 | 22 May 2017 |
32İzleyin | CVE-2023-52169İstismar yok | The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the iCWE-125 | Yüksek8,2 | — | %1,0 | 3 Tem 2024 |
32İzleyin | CVE-2026-48092İstismar yok | 7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)7-zip · 7-zip · CWE-125 | Yüksek8,1 | — | %0,5 | 5 Haz 2026 |
31İzleyin | CVE-2022-29072Kavram kanıtı | 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C7-zip · 7-zip · CWE-787 | Yüksek7,8 | — | %1,5 | 15 Nis 2022 |
31İzleyin | CVE-2026-14266Kavram kanıtı | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability7-zip · 7-zip · CWE-122 | Yüksek7,8 | — | %0,7 | 29 Tem 2026 |
31İzleyin | CVE-2025-11002İstismar yok | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability7-zip · 7-zip · CWE-22 | Yüksek7,8 | — | %0,5 | 23 Oca 2026 |
31İzleyin | CVE-2022-47069İstismar yok | p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7-zip · p7zip · CWE-787 | Yüksek7,8 | — | %0,3 | 22 Ağu 2023 |
29İzleyin | CVE-2007-4725Kavram kanıtı | Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u7-zip · 7-zip · CWE-400 | Orta6,8 | — | %5,6 | 5 Eyl 2007 |
28İzleyin | CVE-2026-48111İstismar yok | GHSL-2026-121 7-Zip UEFI DEPEX OOB Read7-zip · 7-zip · CWE-125 | Yüksek7,1 | — | %0,3 | 5 Haz 2026 |
28İzleyin | CVE-2026-48103İstismar yok | GHSL-2026-119 7-Zip WIM SecurityId OOB read7-zip · 7-zip · CWE-125 | Yüksek7,1 | — | %0,3 | 5 Haz 2026 |
- CVE-2025-041178Bu hafta
7-Zip Mark-of-the-Web Bypass Vulnerability
YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %677-zip · 7-zip25 Oca 2025
- CVE-2023-3110248Planlayın
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
YüksekCVSS 7,8İstismar yokEPSS %577-zip · 7-zip3 Kas 2023
- CVE-2008-653641Planlayın
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suit
KritikCVSS 10,0İstismar yokEPSS %37-zip · 7-zip29 Mar 2009
- CVE-2025-1100139İzleyin
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %277-zip · 7-zip19 Kas 2025
- CVE-2024-1147738İzleyin
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %237-zip · 7-zip22 Kas 2024
- CVE-2016-233538İzleyin
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial
YüksekCVSS 8,8İstismar yokEPSS %10opensuse · opensuse7 Haz 2016
- CVE-2016-233435İzleyin
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to
YüksekCVSS 7,8Kavram kanıtıEPSS %157-zip · 7-zip13 Ara 2016
- CVE-2023-4048135İzleyin
7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %147-zip · 7-zip2 May 2024
- CVE-2026-4809535İzleyin
GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
YüksekCVSS 8,8Kavram kanıtıEPSS %17-zip · 7-zip5 Haz 2026
- CVE-2018-1017235İzleyin
7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemor
YüksekCVSS 8,8İstismar yokEPSS %07-zip · 7-zip16 Nis 2018
- CVE-2023-5216833İzleyin
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite
YüksekCVSS 8,4İstismar yokEPSS %03 Tem 2024
- CVE-2016-929632İzleyin
A null pointer dereference bug affects the 16.02 and many old versions of p7zip.
YüksekCVSS 7,5İstismar yokEPSS %77-zip · p7zip11 Kas 2016
- CVE-2017-1796932İzleyin
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to c
YüksekCVSS 7,8İstismar yokEPSS %57-zip · 7-zip30 Oca 2018
- CVE-2018-1011532İzleyin
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote a
YüksekCVSS 7,8İstismar yokEPSS %57-zip · 7-zip2 May 2018
- CVE-2018-599632İzleyin
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory c
YüksekCVSS 7,8İstismar yokEPSS %37-zip · 7-zip31 Oca 2018
- CVE-2016-780432İzleyin
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL
YüksekCVSS 7,8İstismar yokEPSS %27-zip · 7-zip22 May 2017
- CVE-2023-5216932İzleyin
The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the i
YüksekCVSS 8,2İstismar yokEPSS %13 Tem 2024
- CVE-2026-4809232İzleyin
7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)
YüksekCVSS 8,1İstismar yokEPSS %07-zip · 7-zip5 Haz 2026
- CVE-2022-2907231İzleyin
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>C
YüksekCVSS 7,8Kavram kanıtıEPSS %27-zip · 7-zip15 Nis 2022
- CVE-2026-1426631İzleyin
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %17-zip · 7-zip29 Tem 2026
- CVE-2025-1100231İzleyin
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %17-zip · 7-zip23 Oca 2026
- CVE-2022-4706931İzleyin
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/
YüksekCVSS 7,8İstismar yokEPSS %07-zip · p7zip22 Ağu 2023
- CVE-2007-472529İzleyin
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows u
OrtaCVSS 6,8Kavram kanıtıEPSS %67-zip · 7-zip5 Eyl 2007
- CVE-2026-4811128İzleyin
GHSL-2026-121 7-Zip UEFI DEPEX OOB Read
YüksekCVSS 7,1İstismar yokEPSS %07-zip · 7-zip5 Haz 2026
- CVE-2026-4810328İzleyin
GHSL-2026-119 7-Zip WIM SecurityId OOB read
YüksekCVSS 7,1İstismar yokEPSS %07-zip · 7-zip5 Haz 2026