Upx

Upx

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 18.08.2022 19:15:14
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The h...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 18.08.2022 19:15:14
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 27.05.2021 00:15:08
  • Zuletzt bearbeitet 11.04.2025 12:27:55

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 27.05.2021 00:15:08
  • Zuletzt bearbeitet 11.04.2025 12:27:55

Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 14.05.2021 21:15:07
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 26.03.2021 17:15:13
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from...

  • EPSS 0.17%
  • Veröffentlicht 01.06.2020 14:15:09
  • Zuletzt bearbeitet 11.04.2025 12:27:55

p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 27.12.2019 22:15:11
  • Zuletzt bearbeitet 11.04.2025 12:27:55

An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 27.12.2019 22:15:11
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 27.12.2019 02:15:10
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.