m2team nanazip是m2team团队开源的一个压缩软件。 M2Team NanaZip 6.5.1749.0之前版本存在资源管理错误漏洞,该漏洞源于对UFS和FFS图像处理程序中的超块块大小验证不完整且未验证fs_fsize片段大小,导致攻击者控制的32位字段流入间接块、目录和提取缓冲区分配。特制的UFS镜像在打开或提取过程中可能导致内存耗尽或进程终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55780 | NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() v | |
| CVE-2026-55783 | NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handler | |
| CVE-2026-55782 | NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-cont |
No comments yet