Kde Ark vulnerabilities
5 known vulnerabilities affecting kde/ark.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW2
Vulnerabilities
Page 1 of 1
CVE-2024-57966MEDIUMCVSS 5.0fixed in 24.12.02025-02-03
CVE-2024-57966 [MEDIUM] CWE-36 CVE-2024-57966: libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
cvelistv5nvdosv
CVE-2020-24654LOWCVSS 3.3fixed in 20.08.12020-09-02
CVE-2020-24654 [LOW] CWE-59 CVE-2020-24654: In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extract
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
nvdosv
CVE-2020-16116LOWCVSS 3.3fixed in 20.08.02020-08-03
CVE-2020-16116 [LOW] CWE-22 CVE-2020-16116: In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the ext
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
nvdosv
CVE-2017-5330HIGHCVSS 7.8≤ 16.122017-03-27
CVE-2017-5330 [HIGH] CWE-78 CVE-2017-5330: ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an ar
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
nvdosv
CVE-2011-2725MEDIUMCVSS 6.8≤ 2.172014-02-04
CVE-2011-2725 [MEDIUM] CWE-22 CVE-2011-2725: Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and for
Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.
nvd