Vulnerabilities (CVE)

Filtered by vendor M2team Subscribe
Filtered by product Nanazip
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26282 1 M2team 1 Nanazip 2026-02-20 N/A 6.6 MEDIUM
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.
CVE-2026-27014 1 M2team 1 Nanazip 2026-02-20 N/A 5.5 MEDIUM
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
CVE-2026-27114 1 M2team 1 Nanazip 2026-02-20 N/A 7.5 HIGH
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.