CVE-2025-64031Low· 2.5▾ TwilightPoC availablelibarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar.…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 13.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
2.5 → 4.7
low → medium
0.1%
Last analysed / modified upstream
Exploit / PoC code exists
4.7 → 2.5
medium → low
libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-14164High· 7.5A double free issue has been identified in libarchive's RAR5 reader
CVE-2025-5914High· 7.8A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function
CVE-2026-55194High· 8.7FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-42536High· 7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68…
CVE-2026-65351Medium· 4.3This issue was addressed through improved state management
CVE-2026-34355High· 7.5A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.