This page lists publicly disclosed CVE vulnerabilities affecting freebsd libarchive (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2011-1779 | Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image. | [email protected] | 7.5 | 0.46% | 2012-04-13 | 2026-04-29 |
| CVE-2011-1778 | Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive. | [email protected] | 6.8 | 3.02% | 2012-04-13 | 2026-04-29 |
| CVE-2011-1777 | Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image. | [email protected] | 6.8 | 3.02% | 2012-04-13 | 2026-04-29 |
| CVE-2010-4666 | Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data. | [email protected] | 7.5 | 0.43% | 2012-04-13 | 2026-04-29 |
| CVE-2007-3645 | archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644. | [email protected] | 4.3 | 12.44% | 2007-07-15 | 2026-04-23 |
| CVE-2007-3644 | archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive. | [email protected] | 4.3 | 13.90% | 2007-07-14 | 2026-04-23 |
| CVE-2007-3641 | archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow. | [email protected] | 9.3 | 37.16% | 2007-07-14 | 2026-04-23 |