296,733
Total vulnerabilities in the database
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
| Software | From | Fixed in |
|---|---|---|
| libarchive / libarchive | 3.0.0 | 3.6.2 |
| debian / debian_linux | 10.0 | 10.0.x |
| fedoraproject / fedora | 37 | 37.x |
| splunk / universal_forwarder | 9.1.0 | 9.1.0.x |
| splunk / universal_forwarder | 9.0.0 | 9.0.6 |
| splunk / universal_forwarder | 8.2.0 | 8.2.12 |