Loading market data...
← Back to CVE feed

CVE-2025-15614

LOW CVSS 3.3 View on NVD ↗

Description

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Published: Sep 05, 2026 12:16 UTC Modified: Sep 05, 2026 12:16 UTC