Vulnerabilities > UPX > UPX > 4.2.0

DATE CVE VULNERABILITY TITLE RISK
2025-03-27 CVE-2025-2849 Heap-based Buffer Overflow vulnerability in UPX
A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0.
local
low complexity
upx CWE-122
5.5
2023-01-12 CVE-2023-23456 Out-of-bounds Write vulnerability in multiple products
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file.
local
low complexity
upx fedoraproject CWE-787
5.5
2023-01-12 CVE-2023-23457 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp.
local
low complexity
upx fedoraproject CWE-119
5.5