CVE-2025-29864
- EPSS 0.03%
- Veröffentlicht 03.12.2025 08:13:58
- Zuletzt bearbeitet 04.12.2025 17:15:08
Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 before 12.29.
CVE-2019-12807
- EPSS 0.88%
- Veröffentlicht 13.08.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:37
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an at...
CVE-2018-5196
- EPSS 0.55%
- Veröffentlicht 21.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:18
Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.
CVE-2018-10027
- EPSS 0.07%
- Veröffentlicht 17.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:42
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: %PROGRAMFILES%\ESTsoft\ALZip\Formats, %PROGRAMFILES%\ESTsoft\ALZip\Coders, %PROGRAMFILES(X86)%\ESTso...
CVE-2017-11323
- EPSS 10.43%
- Veröffentlicht 19.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as the initial substring of a filename.
CVE-2011-1336
- EPSS 9.94%
- Veröffentlicht 07.07.2011 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.
CVE-2005-3194
- EPSS 4.82%
- Veröffentlicht 14.10.2005 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code via a long filename in a compressed (1) ALZ, (2) ARJ, (3) ZIP, (4) UUE, or (5) XXE archive.