Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libarchive MEDIUM 5.5
CVE-2025-60753

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s subst…

Fix: after 3.8.1
Fix from $1,600 2025-11-05
Libarchive HIGH 7.5
CVE-2024-48615

Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_su…

Fix: after 3.7.6
Fix from $1,950 2025-03-28
Libarchive HIGH 7.8
CVE-2025-25724

list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspeci…

Fix: after 3.7.7
Fix from $1,950 2025-03-02
Libarchive MEDIUM 5.5
CVE-2025-1632

A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. Th…

Fix: after 3.7.7
Fix from $1,600 2025-02-24
Libarchive HIGH 7.8
CVE-2024-48958

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because s…

Fix: 3.7.5+
Fix from $1,950 2024-10-10
Libarchive HIGH 7.8
CVE-2024-48957

execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because s…

Fix: 3.7.5+
Fix from $1,950 2024-10-10
Libarchive CRITICAL 9.1
CVE-2024-37407

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_centr…

Patch available
Fix from $2,300 2024-06-08
Libarchive MEDIUM 5.3
CVE-2023-30571

Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the uma…

Fix: after 3.6.2
Fix from $1,600 2023-05-29
Libarchive MEDIUM 6.5
CVE-2020-21674

Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of…

Patch available
Fix from $1,600 2020-10-15
Libarchive MEDIUM 5.5
CVE-2019-11463

A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a deni…

Fix: 3.4.0+
Fix from $1,600 2019-04-23
Libarchive HIGH 7.5
CVE-2017-14502

read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an…

Patch available
Fix from $1,950 2017-09-17
Libarchive MEDIUM 6.5
CVE-2017-14501

An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted…

Mitigation only
Fix from $1,600 2017-09-17
Libarchive MEDIUM 6.5
CVE-2017-14503

libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially craf…

Mitigation only
Fix from $1,600 2017-09-17
Libarchive MEDIUM 5.5
CVE-2016-10349

The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-rea…

Patch available
Fix from $1,600 2017-05-01
Libarchive MEDIUM 5.5
CVE-2016-10350

The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial o…

Patch available
Fix from $1,600 2017-05-01
Libarchive MEDIUM 5.5
CVE-2016-10209

The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL point…

Patch available
Fix from $1,600 2017-04-03
Libarchive HIGH 7.5
CVE-2016-8687EPSS 5%

Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a…

Patch available
Fix from $1,950 2017-02-15
Libarchive HIGH 7.5
CVE-2016-8689

The read_Header function in archive_read_support_format_7zip.c in libarchive 3.2.1 allows remote attackers to cause a denial of service (out-of-bound…

Patch available
Fix from $1,950 2017-02-15
Libarchive MEDIUM 5.5
CVE-2016-8688

The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial…

Patch available
Fix from $1,600 2017-02-15
Libarchive HIGH 7.5
CVE-2017-5601

An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-o…

Patch available
Fix from $1,950 2017-01-27
Libarchive HIGH 7.8
CVE-2016-4301

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Libarchive MEDIUM 5.5
CVE-2015-8927

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of ser…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Libarchive MEDIUM 5.5
CVE-2015-8915

bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Libarchive HIGH 8.8
CVE-2016-1541EPSS 10%

Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attack…

Fix: after 3.1.901a
Fix from $1,950 2016-05-07