Vulnerabilities
47 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-39741 | lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. lrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2023-24785 | An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature. An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-48285 | loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. NVD description · AI analysis pending | 7.3 | 1% |
| — | ||
| CVE-2020-36561 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. NVD description · AI analysis pending | 9.1 | 1% | PoC |
| — | |
| CVE-2020-36560 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. NVD description · AI analysis pending | 9.1 | 1% | PoC |
| — | |
| CVE-2021-4217 | A flaw was found in unzip. A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. NVD description · AI analysis pending | 3.3 | <1% | PoC ×2 |
| — | |
| CVE-2021-33453 +1 in the same advisory: …33451 | An issue was discovered in lrzip version 0.641. An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538. NVD description · AI analysis pending | 7.8 group max | <1% | PoC ×2 |
| — | |
| CVE-2022-33067 | Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Predictor::init in libzpaq/libzpaq.cpp. These vulnerabilities allow attackers to cause a Denial of Service via unspecified vectors. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-28044 | Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-26291 | lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2022-0529 +1 in the same advisory: …0530 | A flaw was found in Unzip. A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. NVD description · AI analysis pending | 5.5 | 2% | PoC |
| — | |
| CVE-2022-0401 | Path Traversal in NPM w-zip prior to 1.0.12. Path Traversal in NPM w-zip prior to 1.0.12. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2021-23413 | This affects the package jszip before 3.7.0. This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance. NVD description · AI analysis pending | 5.3 | 3% | PoC ×3 |
| — | |
| CVE-2020-25467 | A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafte A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2020-7730 | The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param. The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2019-16892 | In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). NVD description · AI analysis pending | 5.5 | 2% | PoC |
| — | |
| CVE-2019-13232 | Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issu Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue. NVD description · AI analysis pending | 3.3 | <1% |
| — | ||
| CVE-2019-10654 | The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (in The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2018-18384 | Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size va Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12. NVD description · AI analysis pending | 5.5 | 3% | PoC |
| — | |
| CVE-2018-1002209 | QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that i QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. NVD description · AI analysis pending | 5.5 | 6% |
| — | ||
| CVE-2018-1002204 | adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. NVD description · AI analysis pending | 5.5 | 15% | PoC ×4 |
| — | |
| CVE-2018-13684 | The mintToken function of a smart contract implementation for ZIP, an Ethereum token, has an integer overflow that allows the owner of the contract to set the b The mintToken function of a smart contract implementation for ZIP, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2018-13410 | Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possi Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2018-10860 | perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter. NVD description · AI analysis pending | 7.5 | 49% |
| — | ||
| CVE-2018-1000544 | rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to th rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2018-11496 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2018-10685 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2018-9058 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2018-1000035 | A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a deni A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution. NVD description · AI analysis pending | 7.8 | 30% |
| — | ||
| CVE-2018-5786 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2018-5747 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2018-5650 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2017-9929 +1 in the same advisory: …9928 | In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafte In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. NVD description · AI analysis pending | 5.5 | 1% |
| — | ||
| CVE-2017-8844 | The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive. NVD description · AI analysis pending | 7.8 group max | 2% |
| — | ||
| CVE-2017-8364 | The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibl The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive. NVD description · AI analysis pending | 7.8 | 2% | PoC |
| — | |
| CVE-2017-5946 | The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2016-9844 | Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header. NVD description · AI analysis pending | 4.0 | 2% |
| — |