Vulnerabilities > ARJ Software

DATE CVE VULNERABILITY TITLE RISK
2015-04-08 CVE-2015-2782 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
network
low complexity
debian fedoraproject arj-software CWE-119
7.5
2015-04-08 CVE-2015-0557 Path Traversal vulnerability in multiple products
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
5.8
2015-04-08 CVE-2015-0556 Link Following vulnerability in multiple products
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
5.8