ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-15570
+1 in the same advisory: …15571
A vulnerability was found in ckolivas lrzip up to 0.651.

A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file stream.c. Performing a manipulation results in use after free. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

NVD description · AI analysis pending
1.9<1% PoC ×3
  • ckolivas lrzip
CVE-2025-9396
A security flaw has been discovered in ckolivas lrzip up to 0.651.

A security flaw has been discovered in ckolivas lrzip up to 0.651. This impacts the function __GI_____strtol_l_internal of the file strtol_l.c. Performing manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be exploited.

NVD description · AI analysis pending
1.9<1% PoC ×3
  • ckolivas lrzip