Ckolivas
Products
2- 24 CVEs
- 3 CVEs
Recent CVEs
27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10058 | Hig | 0.58 | 8.8 | 0.04 | Jun 5, 2018 | The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers. | ||
| CVE-2017-8844 | Hig | 0.51 | 7.8 | 0.02 | May 8, 2017 | The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive. | ||
| CVE-2018-11496 | Med | 0.42 | 6.5 | 0.01 | May 26, 2018 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. | ||
| CVE-2018-9058 | Med | 0.36 | 5.5 | 0.01 | Mar 27, 2018 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. | ||
| CVE-2018-5747 | Med | 0.36 | 5.5 | 0.01 | Jan 17, 2018 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. | ||
| CVE-2018-5650 | Med | 0.36 | 5.5 | 0.01 | Jan 12, 2018 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. | ||
| CVE-2017-9929 | Med | 0.36 | 5.5 | 0.01 | Jun 26, 2017 | In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. | ||
| CVE-2017-9928 | Med | 0.36 | 5.5 | 0.01 | Jun 26, 2017 | In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file. | ||
| CVE-2017-8847 | Med | 0.36 | 5.5 | 0.01 | May 8, 2017 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. | ||
| CVE-2017-8846 | Med | 0.36 | 5.5 | 0.02 | May 8, 2017 | The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive. | ||
| CVE-2017-8845 | Med | 0.36 | 5.5 | 0.01 | May 8, 2017 | The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive. | ||
| CVE-2017-8843 | Med | 0.36 | 5.5 | 0.01 | May 8, 2017 | The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive. | ||
| CVE-2017-8842 | Med | 0.36 | 5.5 | 0.02 | May 8, 2017 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive. | ||
| CVE-2025-15570 | Med | 0.34 | 5.3 | 0.00 | Feb 10, 2026 | A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project… | ||
| CVE-2025-15571 | Low | 0.21 | 3.3 | 0.00 | Feb 10, 2026 | A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has… | ||
| CVE-2025-9396 | Low | 0.21 | 3.3 | 0.00 | Aug 24, 2025 | A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been… | ||
| CVE-2023-39741 | 0.00 | — | 0.00 | Aug 17, 2023 | lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | |||
| CVE-2021-33453 | 0.00 | — | 0.00 | Jul 26, 2022 | An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538. | |||
| CVE-2021-33451 | 0.00 | — | 0.00 | Jul 26, 2022 | An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c. | |||
| CVE-2022-33067 | 0.00 | — | 0.01 | Jun 22, 2022 | Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors. |
- risk 0.58cvss 8.8epss 0.04
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
- risk 0.51cvss 7.8epss 0.02
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
- risk 0.42cvss 6.5epss 0.01
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.
- risk 0.36cvss 5.5epss 0.01
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
- risk 0.36cvss 5.5epss 0.01
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
- risk 0.36cvss 5.5epss 0.01
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
- risk 0.36cvss 5.5epss 0.01
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
- risk 0.36cvss 5.5epss 0.01
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
- risk 0.36cvss 5.5epss 0.01
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
- risk 0.36cvss 5.5epss 0.02
The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.
- risk 0.36cvss 5.5epss 0.01
The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.
- risk 0.36cvss 5.5epss 0.01
The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
- risk 0.36cvss 5.5epss 0.02
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project…
- risk 0.21cvss 3.3epss 0.00
A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has…
- risk 0.21cvss 3.3epss 0.00
A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been…
- CVE-2023-39741Aug 17, 2023risk 0.00cvss —epss 0.00
lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2021-33453Jul 26, 2022risk 0.00cvss —epss 0.00
An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
- CVE-2021-33451Jul 26, 2022risk 0.00cvss —epss 0.00
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
- CVE-2022-33067Jun 22, 2022risk 0.00cvss —epss 0.01
Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors.