Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe even though malformed input produces a negative error value. The negative int is converted to the unsigned SizeT destLen and then truncated into outBufWasWrittenSize, causing ReadBlock to trust an attacker-inflated _cachedUnpackBlockSize. During fragment extraction, an attacker-controlled inode Offset can make memcpy read beyond the _cachedBlock heap allocation and place adjacent heap contents in the extracted file, or crash the process. This issue is fixed in stable version 6.0.1698.0 and preview version 6.5.1742.0. Join the discussion | CVE Database V5 | 08/20/2026, 16:11:54 UTC Added: 08/20/2026, 16:22:59 UTC |
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize fragment size, allowing attacker-controlled 32-bit fields to flow into indirect-block, directory, and extraction buffer allocations. A tiny crafted UFS image can force multi-gigabyte allocations during open or extraction, causing memory exhaustion or process termination. This issue is fixed in version 6.5.1749.0. Join the discussion | CVE Database V5 | 08/18/2026, 00:00:00 UTC Added: 07/10/2026, 17:18:19 UTC |
CVE-2026-55780 is a medium severity vulnerability in NanaZip prior to version 6.5.1749.0. It involves improper validation of the extraction buffer size in the .NET single-file bundle handler, which can lead to uncaught exceptions and process crashes. Join the discussion | CVE Database V5 | 08/17/2026, 00:00:00 UTC Added: 07/10/2026, 17:18:19 UTC |
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-house IInArchive handlers in NanaZip.Codecs unconditionally dereference the caller-supplied Indices array inside Extract when the archive engine signals extract everything by passing Indices as NULL and NumItems as 0xFFFFFFFF. This causes a NULL pointer dereference in the standard Test archive or Extract all code path for WebAssembly, ElectronAsar, Zealfs, Romfs, Ufs, Littlefs, and DotNetSingleFile archives, resulting in a process crash. This issue is fixed in version 6.5.1749.0. Join the discussion | CVE Database V5 | 07/10/2026, 16:48:29 UTC Added: 07/10/2026, 17:18:20 UTC |
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination. This issue is fixed in version 6.5.1749.0. Join the discussion | CVE Database V5 | 07/10/2026, 16:46:38 UTC Added: 07/10/2026, 17:18:20 UTC |
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). A 32-bit unsigned integer overflow in the bounds check pos + ht.salt_len > descSize allows an attacker-controlled salt_len field to bypass validation, causing CByteBuffer::CopyFrom to memcpy up to ~4 GiB past the end of a 64. This issue has been patched in stable version 6.0.1698.0 and preview version 6.5.1742.0. Join the discussion | CVE Database V5 | 06/12/2026, 17:06:15 UTC Added: 06/12/2026, 17:55:21 UTC |
NanaZip versions from 3.0.1000.0 up to but not including 6.0.1698.0 contain a heap buffer-overflow read vulnerability in the LVM2 physical-volume metadata parser. This vulnerability is triggered by opening a specially crafted LVM disk image. The issue has been patched in version 6.0.1698.0 and later. Join the discussion | CVE Database V5 | 06/12/2026, 16:57:14 UTC Added: 06/12/2026, 17:09:40 UTC |
NanaZip versions from 3.0.1000.0 up to but not including 6.0.1698.0 contain a heap out-of-bounds read vulnerability in the Android Verified Boot (AVB) vbmeta image parser. This is caused by an unsigned integer underflow in a bounds check, allowing a crafted .avb or .img file to trigger a read beyond the allocated buffer, leading to a deterministic crash (denial of service). The issue has been patched in version 6.0.1698.0 and later. Join the discussion | CVE Database V5 | 06/12/2026, 16:56:47 UTC Added: 06/12/2026, 17:09:40 UTC |
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS filesystem image. The attacker controls the byte offset of the write within a ~254-byte window past the heap allocation boundary. This vulnerability is fixed in 6.0.1698.0. Join the discussion | CVE Database V5 | 05/12/2026, 19:23:43 UTC Added: 05/12/2026, 19:36:31 UTC |
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPaths recurses into subdirectories without any depth limit or visited-inode tracking. A crafted UFS image with a deep directory tree or an inode cycle causes stack exhaustion, crashing the NanaZip process. This vulnerability is fixed in 6.0.1698.0. Join the discussion | CVE Database V5 | 05/12/2026, 19:22:59 UTC Added: 05/12/2026, 19:36:28 UTC |
Showing 1 to 10 of 18 results