libarchive kayıtları
libarchive üreticisine ait 76 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %93,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read23
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-476 NULL Pointer Dereference9
- CWE-190 Integer Overflow or Wraparound8
- CWE-20 Improper Input Validation5
- CWE-416 Use After Free3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
76 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2024-26256İstismar yok | Libarchive Remote Code Execution Vulnerabilitylibarchive · libarchive · CWE-122 | Yüksek7,8 | — | %84,8 | 9 Nis 2024 |
40Planlayın | CVE-2022-36227İstismar yok | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if thlibarchive · libarchive · CWE-476 | Kritik9,8 | — | %2,4 | 21 Kas 2022 |
38İzleyin | CVE-2016-1541İstismar yok | Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remolibarchive · libarchive · CWE-20 | Yüksek8,8 | — | %10,3 | 7 May 2016 |
36İzleyin | CVE-2016-6250İstismar yok | Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) olibarchive · libarchive · CWE-190 | Yüksek8,6 | — | %6,3 | 21 Eyl 2016 |
36İzleyin | CVE-2018-1000877İstismar yok | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerablibarchive · libarchive · CWE-415 | Yüksek8,8 | — | %4,6 | 20 Ara 2018 |
36İzleyin | CVE-2018-1000878İstismar yok | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnelibarchive · libarchive · CWE-416 | Yüksek8,8 | — | %4,4 | 20 Ara 2018 |
36İzleyin | CVE-2020-9308İstismar yok | archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a libarchive · libarchive · CWE-787 | Yüksek8,8 | — | %2,3 | 20 Şub 2020 |
36İzleyin | CVE-2024-37407İstismar yok | Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.libarchive · libarchive · CWE-125 | Kritik9,1 | — | %1,0 | 8 Haz 2024 |
34İzleyin | CVE-2015-8921İstismar yok | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-boundlibarchive · libarchive · CWE-125 | Yüksek7,5 | — | %12,0 | 20 Eyl 2016 |
32İzleyin | CVE-2016-8687İstismar yok | Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of servlibarchive · libarchive · CWE-119 | Yüksek7,5 | — | %5,3 | 15 Şub 2017 |
32İzleyin | CVE-2016-4300İstismar yok | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackerlibarchive · libarchive · CWE-190 | Yüksek7,8 | — | %4,9 | 21 Eyl 2016 |
32İzleyin | CVE-2016-4302İstismar yok | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackelibarchive · libarchive · CWE-119 | Yüksek7,8 | — | %4,8 | 21 Eyl 2016 |
32İzleyin | CVE-2016-4301İstismar yok | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attlibarchive · libarchive · CWE-119 | Yüksek7,8 | — | %3,7 | 21 Eyl 2016 |
32İzleyin | CVE-2015-8931İstismar yok | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive blibarchive · libarchive · CWE-190 | Yüksek7,8 | — | %2,1 | 20 Eyl 2016 |
31İzleyin | CVE-2016-4809İstismar yok | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers tlibarchive · libarchive · CWE-20 | Yüksek7,5 | — | %4,8 | 21 Eyl 2016 |
31İzleyin | CVE-2016-5418İstismar yok | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attalibarchive · libarchive · CWE-19 | Yüksek7,5 | — | %4,7 | 21 Eyl 2016 |
31İzleyin | CVE-2015-8919İstismar yok | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause libarchive · libarchive · CWE-119 | Yüksek7,5 | — | %4,5 | 20 Eyl 2016 |
31İzleyin | CVE-2017-5601İstismar yok | An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to triggerlibarchive · libarchive · CWE-125 | Yüksek7,5 | — | %4,5 | 27 Oca 2017 |
31İzleyin | CVE-2015-8917İstismar yok | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid clibarchive · libarchive · CWE-476 | Yüksek7,5 | — | %4,3 | 20 Eyl 2016 |
31İzleyin | CVE-2015-8930İstismar yok | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is alibarchive · libarchive · CWE-20 | Yüksek7,5 | — | %4,3 | 20 Eyl 2016 |
31İzleyin | CVE-2019-18408İstismar yok | archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_libarchive · libarchive · CWE-416 | Yüksek7,5 | — | %4,0 | 24 Eki 2019 |
31İzleyin | CVE-2015-8918İstismar yok | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (craslibarchive · libarchive · CWE-119 | Yüksek7,5 | — | %3,8 | 20 Eyl 2016 |
31İzleyin | CVE-2017-14502İstismar yok | read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leadlibarchive · libarchive · CWE-125 | Yüksek7,5 | — | %3,4 | 17 Eyl 2017 |
31İzleyin | CVE-2016-8689İstismar yok | The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (outlibarchive · libarchive · CWE-125 | Yüksek7,5 | — | %3,3 | 15 Şub 2017 |
31İzleyin | CVE-2024-48958İstismar yok | execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file libarchive · libarchive · CWE-125 | Yüksek7,8 | — | %0,6 | 9 Eki 2024 |
- CVE-2024-2625656Planlayın
Libarchive Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %85libarchive · libarchive9 Nis 2024
- CVE-2022-3622740Planlayın
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if th
KritikCVSS 9,8İstismar yokEPSS %2libarchive · libarchive21 Kas 2022
- CVE-2016-154138İzleyin
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remo
YüksekCVSS 8,8İstismar yokEPSS %10libarchive · libarchive7 May 2016
- CVE-2016-625036İzleyin
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) o
YüksekCVSS 8,6İstismar yokEPSS %6libarchive · libarchive21 Eyl 2016
- CVE-2018-100087736İzleyin
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerab
YüksekCVSS 8,8İstismar yokEPSS %5libarchive · libarchive20 Ara 2018
- CVE-2018-100087836İzleyin
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulne
YüksekCVSS 8,8İstismar yokEPSS %4libarchive · libarchive20 Ara 2018
- CVE-2020-930836İzleyin
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a
YüksekCVSS 8,8İstismar yokEPSS %2libarchive · libarchive20 Şub 2020
- CVE-2024-3740736İzleyin
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled.
KritikCVSS 9,1İstismar yokEPSS %1libarchive · libarchive8 Haz 2024
- CVE-2015-892134İzleyin
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bound
YüksekCVSS 7,5İstismar yokEPSS %12libarchive · libarchive20 Eyl 2016
- CVE-2016-868732İzleyin
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of serv
YüksekCVSS 7,5İstismar yokEPSS %5libarchive · libarchive15 Şub 2017
- CVE-2016-430032İzleyin
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attacker
YüksekCVSS 7,8İstismar yokEPSS %5libarchive · libarchive21 Eyl 2016
- CVE-2016-430232İzleyin
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attacke
YüksekCVSS 7,8İstismar yokEPSS %5libarchive · libarchive21 Eyl 2016
- CVE-2016-430132İzleyin
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote att
YüksekCVSS 7,8İstismar yokEPSS %4libarchive · libarchive21 Eyl 2016
- CVE-2015-893132İzleyin
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive b
YüksekCVSS 7,8İstismar yokEPSS %2libarchive · libarchive20 Eyl 2016
- CVE-2016-480931İzleyin
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %5libarchive · libarchive21 Eyl 2016
- CVE-2016-541831İzleyin
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote atta
YüksekCVSS 7,5İstismar yokEPSS %5libarchive · libarchive21 Eyl 2016
- CVE-2015-891931İzleyin
The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause
YüksekCVSS 7,5İstismar yokEPSS %5libarchive · libarchive20 Eyl 2016
- CVE-2017-560131İzleyin
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger
YüksekCVSS 7,5İstismar yokEPSS %5libarchive · libarchive27 Oca 2017
- CVE-2015-891731İzleyin
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid c
YüksekCVSS 7,5İstismar yokEPSS %4libarchive · libarchive20 Eyl 2016
- CVE-2015-893031İzleyin
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a
YüksekCVSS 7,5İstismar yokEPSS %4libarchive · libarchive20 Eyl 2016
- CVE-2019-1840831İzleyin
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_
YüksekCVSS 7,5İstismar yokEPSS %4libarchive · libarchive24 Eki 2019
- CVE-2015-891831İzleyin
The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (cras
YüksekCVSS 7,5İstismar yokEPSS %4libarchive · libarchive20 Eyl 2016
- CVE-2017-1450231İzleyin
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, lead
YüksekCVSS 7,5İstismar yokEPSS %3libarchive · libarchive17 Eyl 2017
- CVE-2016-868931İzleyin
The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out
YüksekCVSS 7,5İstismar yokEPSS %3libarchive · libarchive15 Şub 2017
- CVE-2024-4895831İzleyin
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file
YüksekCVSS 7,8İstismar yokEPSS %1libarchive · libarchive9 Eki 2024