Long Range Zip
Vendor:
First CVE: May 8, 2017 · Active for 9 years
23
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Long Range Zip over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2017
9 years ago
Most Recent CVE
Aug 17, 2023
1,074 days ago
CVE Severity & Scoring
Long Range Zip23 CVEs
87%
9%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local21 (91.3%)
Network2 (8.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.3%)
Unknown0 (0.0%)
Required22 (95.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None23 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10685CRITICAL In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (applicat | May 2, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-8844HIGH The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly h | May 8, 2017 | 7.8 | 26 | NO | NO |
CVE-2021-33453HIGH An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538. | Jul 26, 2022 | 7.8 | 24 | NO | NO |
CVE-2018-11496MEDIUM In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. | May 26, 2018 | 6.5 | 23 | NO | NO |
CVE-2022-26291MEDIUM lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to | Mar 28, 2022 | 5.5 | 21 | NO | NO |
CVE-2018-5786MEDIUM In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to ca | Jan 19, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-5747MEDIUM In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of servi | Jan 17, 2018 | 5.5 | 21 | NO | NO |
CVE-2018-5650MEDIUM In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to c | Jan 12, 2018 | 5.5 | 21 | NO | NO |
CVE-2017-9929MEDIUM In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. | Jun 26, 2017 | 5.5 | 21 | NO | NO |
CVE-2017-9928MEDIUM In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file. | Jun 26, 2017 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Long Range Zip
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.651 | 2 | 5.5 | 0.5% | 0 | 0 |
| 0.641 | 3 | 6.3 | 0.5% | 0 | 0 |
| 0.631 | 17 | 6.0 | 1.3% | 0 | 0 |
| 0.621 | 1 | 5.5 | 0.9% | 0 | 0 |