CVE-2016-4809
- EPSS 2.54%
- Veröffentlicht 21.09.2016 14:25:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
CVE-2016-4302
- EPSS 1.21%
- Veröffentlicht 21.09.2016 14:25:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
CVE-2016-4301
- EPSS 1.37%
- Veröffentlicht 21.09.2016 14:25:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.
CVE-2016-4300
- EPSS 0.91%
- Veröffentlicht 21.09.2016 14:25:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buf...
CVE-2015-8934
- EPSS 1.36%
- Veröffentlicht 20.09.2016 14:15:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
CVE-2015-8933
- EPSS 0.31%
- Veröffentlicht 20.09.2016 14:15:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.
CVE-2015-8931
- EPSS 0.27%
- Veröffentlicht 20.09.2016 14:15:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefin...
CVE-2015-8932
- EPSS 0.56%
- Veröffentlicht 20.09.2016 14:15:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
CVE-2015-8930
- EPSS 4.8%
- Veröffentlicht 20.09.2016 14:15:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
CVE-2015-8929
- EPSS 0.25%
- Veröffentlicht 20.09.2016 14:15:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.