Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

M2Team — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting M2Team. AI-powered Chinese analysis, POCs, and references for each vulnerability.

M2Team develops software primarily used in enterprise environments, with their products focusing on system management and remote access solutions. Historically, their vulnerabilities have commonly included remote code execution, cross-site scripting, and privilege escalation flaws. The team has addressed multiple critical security issues, with six CVEs currently documented in their record. While no major public security incidents have been widely reported, their vulnerability history suggests a pattern of input validation weaknesses and insufficient access controls in their software. Security researchers have noted that patches for their issues often arrive with significant delays, leaving exposed systems vulnerable to exploitation for extended periods.

Found 21 results / 21 Clear Filters
Top products by M2Team: NanaZip
CVE ID Title CVSS Severity Published
CVE-2026-54616 NanaZip: Heap out-of-bounds read in NanaZip SquashFS LZ4 decompressor via unchecked negative return value — NanaZip CWE-125 7.1 High 2026-08-20
CVE-2026-55781 NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields — NanaZip CWE-400 - - 2026-07-10
CVE-2026-55780 NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size — NanaZip CWE-248 - - 2026-07-10
CVE-2026-55783 NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive — NanaZip CWE-476 - - 2026-07-10
CVE-2026-55782 NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields — NanaZip CWE-400 - - 2026-07-10
CVE-2026-47223 NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow — NanaZip CWE-125 5.4 Medium 2026-06-12
CVE-2026-47224 NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check — NanaZip CWE-125 4.3 Medium 2026-06-12
CVE-2026-47222 NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow — NanaZip CWE-125 5.4 Medium 2026-06-12
CVE-2026-44215 NanaZip: Heap out-of-bounds write in NanaZip UFS directory parser — NanaZip CWE-787 4.4 Medium 2026-05-12
CVE-2026-42445 NanaZip: Uncontrolled recursion in NanaZip UFS directory traversal causes stack exhaustion — NanaZip CWE-674 3.3 Low 2026-05-12
CVE-2026-42444 NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount — NanaZip CWE-770 3.3 Low 2026-05-12
CVE-2026-42443 NanaZip: Integer divide-by-zero in NanaZip UFS inode offset calculation — NanaZip CWE-369 3.3 Low 2026-05-12
CVE-2026-42442 NanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlink — NanaZip CWE-476 3.3 Low 2026-05-12
CVE-2026-42355 NanaZip: Uncontrolled recursion in NanaZip Electron ASAR parser causes stack exhaustion — NanaZip CWE-674 3.3 Low 2026-05-12
CVE-2026-42446 NanaZip: Stack out-of-bounds read in NanaZip ZealFS bitmap parser — NanaZip CWE-125 4.4 Medium 2026-05-12
CVE-2026-27711 NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length — NanaZip CWE-125 7.8AI High AI 2026-02-25
CVE-2026-27710 NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS) — NanaZip CWE-191 7.5AI High AI 2026-02-25
CVE-2026-27709 NanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked RelativePathLength — NanaZip CWE-125 9.1AI Critical AI 2026-02-25
CVE-2026-27114 NanaZip has ROMFS Archive Infinite Loop — NanaZip CWE-835 7.5 - 2026-02-19
CVE-2026-27014 NanZip has ROMFS Archive Infinite Loop / Stack Overflow — NanaZip CWE-674 6.2 - 2026-02-19
CVE-2026-26282 NanaZip has DotNet Single file OOB Heap Read — NanaZip CWE-126 7.1 - 2026-02-19

This page lists every published CVE security advisory associated with M2Team. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.