<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:09:36 +0000</lastBuildDate>
    <item>
      <title>7PAA023732 — System 800xA affected by 3rd party component vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/7paa023732</link>
      <description>&lt;p&gt;ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip.&lt;/p&gt;
&lt;p&gt;Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards.&lt;/p&gt;
&lt;p&gt;These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip.&lt;/p&gt;
&lt;p&gt;Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards.&lt;/p&gt;
&lt;p&gt;These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/7paa023732</guid>
    </item>
    <item>
      <title>bdu:2024-11604</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11604</link>
      <description>bdu:2024-11604</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11604</guid>
    </item>
    <item>
      <title>EUVD-2026-258483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258483</link>
      <description>EUVD-2026-258483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258483</guid>
    </item>
    <item>
      <title>fkie_cve-2023-52169</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52169</link>
      <description>&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-52169</guid>
    </item>
    <item>
      <title>GHSA-g8p4-4qgr-rf4f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g8p4-4qgr-rf4f</link>
      <description>&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g8p4-4qgr-rf4f</guid>
    </item>
    <item>
      <title>gsd-2023-52169</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-52169</link>
      <description>gsd-2023-52169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-52169</guid>
    </item>
    <item>
      <title>OESA-2025-1748 — p7zip security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1748</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: p7zip, openEuler:20.03-LTS-SP4: p7zip, openEuler:22.03-LTS-SP3: p7zip, openEuler:22.03-LTS-SP4: p7zip, openEuler:24.03-LTS: p7zip, openEuler:24.03-LTS-SP1: p7zip&lt;/p&gt;
&lt;p&gt;7za for Linux system to archive file as 7z file format&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.(CVE-2023-52168)&lt;/p&gt;
&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.(CVE-2023-52169)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: p7zip, openEuler:20.03-LTS-SP4: p7zip, openEuler:22.03-LTS-SP3: p7zip, openEuler:22.03-LTS-SP4: p7zip, openEuler:24.03-LTS: p7zip, openEuler:24.03-LTS-SP1: p7zip&lt;/p&gt;
&lt;p&gt;7za for Linux system to archive file as 7z file format&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.(CVE-2023-52168)&lt;/p&gt;
&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.(CVE-2023-52169)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1748</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2475-1 — Security update for p7zip</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2475-1</link>
      <description>&lt;p&gt;Security update for p7zip&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for p7zip&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2475-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-52169</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52169</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: 7zip, Ubuntu:Pro:24.04:LTS: 7zip&lt;/p&gt;
&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: 7zip, Ubuntu:Pro:24.04:LTS: 7zip&lt;/p&gt;
&lt;p&gt;The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52169</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1516 — 7-Zip: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1516</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in 7-Zip ausnutzen, um Dateien zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in 7-Zip ausnutzen, um Dateien zu manipulieren oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1516</guid>
    </item>
  </channel>
</rss>
