Search CVE reports


Toggle filters

121 – 130 of 171 results


CVE-2017-5979

Medium priority

Some fixes available 4 of 5

The prescan_entry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.

1 affected package

zziplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zziplib — — — — —
Show less packages

CVE-2017-5978

Medium priority

Some fixes available 4 of 5

The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ZIP file.

1 affected package

zziplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zziplib — — — — —
Show less packages

CVE-2017-5976

Medium priority

Some fixes available 4 of 5

Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted...

1 affected package

zziplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zziplib — — — — —
Show less packages

CVE-2017-5975

Medium priority

Some fixes available 4 of 5

Heap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

1 affected package

zziplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zziplib — — — — —
Show less packages

CVE-2017-5974

Medium priority

Some fixes available 4 of 5

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

1 affected package

zziplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zziplib — — — — —
Show less packages

CVE-2017-5946

Medium priority

Some fixes available 1 of 3

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to...

2 affected packages

ruby-zip, libzip-ruby

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-zip Not affected Not affected Not affected Not affected Not affected
libzip-ruby Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2016-9844

Negligible priority

Some fixes available 2 of 6

Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.

1 affected package

unzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unzip — — — Not affected Not affected
Show less packages

CVE-2014-9913

Negligible priority

Some fixes available 2 of 5

Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.

1 affected package

unzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unzip — — — Not affected Not affected
Show less packages

CVE-2016-2334

Medium priority
Ignored

Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.

1 affected package

p7zip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
p7zip — — — — Not affected
Show less packages

CVE-2016-9296

Low priority
Ignored

A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams...

1 affected package

p7zip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
p7zip — — — — Not affected
Show less packages