CVE-2026-42444
- EPSS 0.11%
- Veröffentlicht 12.05.2026 19:22:09
- Zuletzt bearbeitet 18.05.2026 14:17:41
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method reads BlockCount directly from the attacker-controlle...
CVE-2026-42443
- EPSS 0.11%
- Veröffentlicht 12.05.2026 19:21:31
- Zuletzt bearbeitet 18.05.2026 13:46:34
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the superblock fi...
CVE-2026-42442
- EPSS 0.11%
- Veröffentlicht 12.05.2026 19:21:04
- Zuletzt bearbeitet 18.05.2026 13:51:59
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the root inode (...
CVE-2026-42355
- EPSS 0.11%
- Veröffentlicht 12.05.2026 19:20:35
- Zuletzt bearbeitet 18.05.2026 13:52:21
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, bo...
CVE-2026-42446
- EPSS 0.12%
- Veröffentlicht 12.05.2026 19:19:44
- Zuletzt bearbeitet 14.05.2026 15:49:25
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted ZealFS v1 filesystem image. ...
CVE-2026-27711
- EPSS 0.14%
- Veröffentlicht 25.02.2026 23:44:26
- Zuletzt bearbeitet 27.02.2026 17:51:29
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory ...
- EPSS 0.13%
- Veröffentlicht 25.02.2026 23:43:28
- Zuletzt bearbeitet 27.02.2026 17:53:13
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer...
CVE-2026-27709
- EPSS 0.14%
- Veröffentlicht 25.02.2026 23:39:03
- Zuletzt bearbeitet 27.02.2026 17:54:12
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulnerability in manifest parsing. A crafted bundle can ...
CVE-2026-27114
- EPSS 0.27%
- Veröffentlicht 19.02.2026 21:18:32
- Zuletzt bearbeitet 26.02.2026 00:16:23
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
CVE-2026-27014
- EPSS 0.15%
- Veröffentlicht 19.02.2026 20:45:07
- Zuletzt bearbeitet 20.02.2026 19:27:51
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive ...