Bandisoft Bandizip 3.07

CPE Details

Bandisoft Bandizip 3.07
3.07
2014-02-14
16h04 +00:00
2014-02-14
16h18 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:bandisoft:bandizip:3.07:*:*:*:*:*:*:*

Informations

Vendor

bandisoft

Product

bandizip

Version

3.07

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-33027 2025-04-15 00h00 +00:00 In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, Bandizip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user.
7.8
High
CVE-2021-26623 2022-04-01 20h17 +00:00 A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.
9.8
Critical
CVE-2014-1680 2014-02-14 01h00 +00:00 Untrusted search path vulnerability in Bandisoft Bandizip before 3.10 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory.
6.9