Home/Product/7 zip 7 zip
Product

7 zip 7 zip

26 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-11002
all versions
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec
7.8HIGH
CVE-2025-11001
all versions
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec
7.8HIGH
CVE-2025-55188
< 25.01
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
3.6LOW
CVE-2025-53817
< 25.00
7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0
7.5HIGH
CVE-2025-53816
< 25.00
7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corr
7.5HIGH
CVE-2022-47112
all versions
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions a
2.5LOW
CVE-2022-47111
all versions
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions ar
2.5LOW
CVE-2025-0411
< 24.09
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection me
7.0HIGH
CVE-2024-11612
>= 24.06 and < 24.08
7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-se
6.5MEDIUM
CVE-2024-11477
< 24.07
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to
7.8HIGH
CVE-2023-40481
all versions
7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to
7.8HIGH
CVE-2023-31102
< 22.01
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
7.8HIGH
CVE-2022-47069
all versions
p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(boo
7.8HIGH
CVE-2022-29072
<= 21.07
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to
7.8HIGH
CVE-2018-10115
<= 18.03
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowin
7.8HIGH
CVE-2018-10172
<= 18.01
7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the S
8.8HIGH
CVE-2018-5996
< 18.00
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multipl
7.8HIGH
CVE-2017-17969
< 18.00
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote atta
7.8HIGH
CVE-2016-7804
<= 16.02
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan
7.8HIGH
CVE-2016-2334
<= 15.14
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote at
7.8HIGH
CVE-2016-9296
all versions
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable fol
7.5HIGH
CVE-2016-2335
all versions
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to caus
8.8HIGH
CVE-2015-1038
all versions
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
CVE-2008-6536
<= 4.56
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME
CVE-2007-4725
<= 4.42
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta
CVE-2005-3051
all versions
Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin