Tag

Buffer Overflow

All articles tagged with #buffer overflow

7-Zip XZ Decoder Overflow Could Let Crafted Archives Execute Code
security1 month ago

7-Zip XZ Decoder Overflow Could Let Crafted Archives Execute Code

A heap-based buffer overflow in 7-Zip’s XZ decoding pipeline (CVE-2026-14266) can trigger when processing crafted XZ data, allowing code execution within the 7-Zip process. The fix in 7-Zip 26.02 corrects how remaining buffer space is tracked to prevent out-of-bounds writes. It’s a local attack vector requiring the user to open the file, with Windows processes typically running under limited rights, mitigating potential impact. ZDI rates the flaw as High (7.0); as of July 20, 2026, no public PoC or exploitation in the wild is known. Users should manually update to 7-Zip 26.02 or later on all machines, since the patch was released before disclosure and won’t auto-install on stand-alone systems.

Ivanti Avalanche: Critical Security Flaws Threaten Thousands of Organizations
software-security-cyber-threat3 years ago

Ivanti Avalanche: Critical Security Flaws Threaten Thousands of Organizations

Multiple critical security flaws have been discovered in Ivanti Avalanche, a mobile device management solution used by 30,000 organizations. The vulnerabilities, including stack-based buffer overflows, could allow remote attackers to execute code or crash systems. Ivanti has released a patch to address the issues, along with six other flaws that could lead to authentication bypass and remote code execution. Users are urged to update their software promptly to mitigate potential threats.

Zyxel Firewall and VPN Devices Face Critical Security Threats
network-security-vulnerability3 years ago

Zyxel Firewall and VPN Devices Face Critical Security Threats

Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers to achieve code execution. Both the flaws are buffer overflow vulnerabilities and are rated 9.8 out of 10 on the CVSS scoring system. The impacted devices include ATP, USG FLEX, USG FLEX50(W) / USG20(W)-VPN, VPN, and ZyWALL/USG. Security researchers from TRAPA Security and STAR Labs SG have been credited with discovering and reporting the flaws.