peter bassill · operator
$ cve CVE-2016-1925 JSON

CVE-2016-1925

9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.99% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-191
On CISA KEVno
Public exploitnone known
Published2017-01-23
Last modified2026-06-17

Affected (1)

VendorProduct
lha for unix projectlha for unix

References

→ the Explorer  ·  watch your stack  ·  NVD