Ponsoftware develops file-archive and decompression utilities such as ExplZh and Archive Decoder, where the vulnerability profile concentrates on memory-safety and path-handling weaknesses including classic buffer overflows, path traversal, and untrusted search path issues. These are characteristic of utility software that processes untrusted archive contents and system paths with limited input validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ponsoftware over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2434HIGH Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header | Jun 25, 2010 | 9.3 | 28 | NO | NO |
CVE-2018-0646HIGH Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors. | Sep 4, 2018 | 7.8 | 26 | NO | NO |
CVE-2010-3159MEDIUM Untrusted search path vulnerability in Explzh 5.67 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory. | Oct 25, 2010 | 6.9 | 22 | NO | NO |
CVE-2010-3160MEDIUM Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory. | Oct 25, 2010 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ponsoftware.
Media articles that mention a CVE ID that affects a product developed by Ponsoftware — matched by CVE ID, not by vendor name.