VYPR

rpm package

opensuse/7zip&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/7zip&distro=openSUSE%20Tumbleweed

Vulnerabilities (11)

  • CVE-2026-14266HigJul 29, 2026
    affected < 26.02-1.1fixed 26.02-1.1

    7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit

  • CVE-2026-48112MedJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A 4-byte heap out-of-bounds read exists in the Unix ar archive parser in 7-Zip. When parsing a BSD-style __.SYMDEF symbol t

  • CVE-2026-48111MedJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedencyExpression function of the UEFI firmware image parser(CPP/7zip/Archive/UefiHandler.cpp). The function validates an attac

  • CVE-2026-48104MedJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused by a sparsely populated index array. In the SquashFS handler, _blockToNode is allocated with capacity for every metadata b

  • CVE-2026-48103MedJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) archive handler's security descriptor lookup. In CHandler::GetSecurity (CPP/7zip/Archive/Wim/WimHandler.cpp), the per-ima

  • CVE-2026-48102LowJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File Identifier Descriptor parser. In CFileId::Parse (CPP/7zip/Archive/Udf/UdfIn.cpp), after validating size < 38

  • CVE-2026-48101MedJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer of attacker-declared CapsuleImageSize (up

  • CVE-2026-48095HigJun 5, 2026
    affected < 26.01-1.1fixed 26.01-1.1

    7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution

  • CVE-2026-48092MedJun 5, 2026
    affected < 26.02-2.1fixed 26.02-2.1

    7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset integer overflow on 32-bit builds. 32-bit integer overflow in the SquashFS ReadBlock function allows an attacker-controlled node.Offse

  • CVE-2025-53817HigJul 17, 2025
    affected < 25.01-1.1fixed 25.01-1.1

    7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference in the Compound handler may lead to denial of service. Version 25.0.0 contains a fix cor the issue.

  • CVE-2025-53816HigJul 17, 2025
    affected < 25.01-1.1fixed 25.01-1.1

    7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.