Chitora maintains a narrowly scoped security profile centered on the LHAZ compression utility, a niche but functionally important tool in file-handling workflows. The recurring exposure reflects an untrusted search path weakness class, a structural vulnerability in how the application resolves external dependencies during execution. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chitora over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2247HIGH Untrusted search path vulnerability in Self-extracting archive files created by Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an un | Jul 17, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-2249HIGH Untrusted search path vulnerability in Self-extracting archive files created by Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an u | Jul 17, 2017 | 7.8 | 21 | NO | NO |
CVE-2017-2248HIGH Untrusted search path vulnerability in Installer of Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Jul 17, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-2246HIGH Untrusted search path vulnerability in Installer of Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Jul 17, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chitora.
Media articles that mention a CVE ID that affects a product developed by Chitora — matched by CVE ID, not by vendor name.