Skip to main content

Vendor/product archive

cabextract_project / cabextract CVEs

Beta · best-effort

9 CVEs tagged to cabextract_project / cabextract0 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2018-14679

Published Jul 28, 2018

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial o…

CVSS 6.5 · Medium

CVE-2010-2801

Published Aug 9, 2010

Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2800

Published Aug 9, 2010

The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) tes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0916

Published Jan 27, 2005

Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1