Lhaz is a compression utility with a narrowly scoped product portfolio focused on file archiving and decompression functionality. The limited disclosure history centers on the core Lhaz product, and current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lhaz over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4428MEDIUM Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-20 | Aug 20, 2007 | 6.8 | 20 | NO | NO |
CVE-2006-4116MEDIUM Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filenam | Aug 14, 2006 | 5.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lhaz.
Media articles that mention a CVE ID that affects a product developed by Lhaz — matched by CVE ID, not by vendor name.