CVE-2026-54616
- EPSS -
- Veröffentlicht 20.08.2026 16:11:54
- Zuletzt bearbeitet 20.08.2026 20:17:34
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rej...
CVE-2026-55783
- EPSS 0.11%
- Veröffentlicht 10.07.2026 17:17:00
- Zuletzt bearbeitet 10.07.2026 19:17:26
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-house IInArchive handlers in NanaZip.Codecs unconditionally dereference the caller-supplied Indices array inside Extract when the arch...
CVE-2026-55782
- EPSS 0.11%
- Veröffentlicht 10.07.2026 17:17:00
- Zuletzt bearbeitet 14.07.2026 02:16:56
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name...
CVE-2026-55781
- EPSS 0.11%
- Veröffentlicht 10.07.2026 17:16:59
- Zuletzt bearbeitet 10.07.2026 21:16:57
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does ...
CVE-2026-55780
- EPSS 0.31%
- Veröffentlicht 10.07.2026 17:16:59
- Zuletzt bearbeitet 13.07.2026 19:17:15
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, wh...
CVE-2026-47224
- EPSS 0.19%
- Veröffentlicht 12.06.2026 17:16:24
- Zuletzt bearbeitet 15.06.2026 20:59:13
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the LVM2 physical-volume metadata parser in NanaZip (via the upstream 7-Zip LvmHan...
CVE-2026-47222
- EPSS 0.17%
- Veröffentlicht 12.06.2026 17:16:24
- Zuletzt bearbeitet 15.06.2026 20:59:13
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Z...
CVE-2026-47223
- EPSS 0.18%
- Veröffentlicht 12.06.2026 17:06:15
- Zuletzt bearbeitet 15.06.2026 20:59:13
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Z...
CVE-2026-44215
- EPSS 0.22%
- Veröffentlicht 12.05.2026 19:23:43
- Zuletzt bearbeitet 14.05.2026 15:48:22
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS filesystem ima...
CVE-2026-42445
- EPSS 0.11%
- Veröffentlicht 12.05.2026 19:22:59
- Zuletzt bearbeitet 14.05.2026 15:54:37
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPaths recurses into subdirectories without any depth l...