Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 6.1% | — | Canonical Ubuntu LinuxDebian LinuxUnzip Project Unzip | 6/11/2015 | 17/6/2026 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive. | |
| Modificada | Media (6.8) | 7.2% | — | Canonical Ubuntu LinuxDebian LinuxUnzip Project Unzip | 6/11/2015 | 17/6/2026 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value. | |
| Modificada | Alta (7.5) | 4.9% | — | Canonical Ubuntu LinuxInfo-zip Unzip | 23/2/2015 | 17/6/2026 | Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8. | |
| Modificada | Media (5) | 12% | — | Unzip Project UnzipCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 6/2/2015 | 17/6/2026 | unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression. | |
| Modificada | Media (5.8) | 1.5% | — | R-company Unzipper | 18/3/2014 | 17/6/2026 | Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename. | |
| Analizada | Alta (9.3) | 6.3% | — | Canonical Ubuntu LinuxApple MAC OS XDebian LinuxUnzip Project Unzip | 17/3/2008 | 16/6/2026 | The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data. | |
| Modificada | Media (5.1) | 3.6% | — | CAM Development CAM UnzipErik Dienske AbaktRoger Aelbrecht Tzipbuilder | 9/5/2006 | 16/6/2026 | Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and 0.9.3-beta1, (3) CAM UnZip 4.0 and 4.3, and possibly other products, allows user-assisted attackers to execute arbitrary code via a ZIP archive that contains a file with a long file name. | |
| Modificada | Baja (3.7) | 1.5% | — | Info-zip Unzip | 31/12/2005 | 16/6/2026 | Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is… | |
| Modificada | Baja (1.2) | 0.40% | — | Info-zip Unzip | 5/8/2005 | 16/6/2026 | Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete. | |
| Modificada | Media (6.2) | 0.40% | — | Info-zip Unzip | 2/5/2005 | 16/6/2026 | Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges. | |
| Modificada | Baja (2.6) | 22% | — | Info-zip UnzipSCO Openlinux ServerSCO Openlinux Workstation | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence. | |
| Modificada | Baja (2.1) | 0.50% | — | Info-zip Unzip | 12/7/2001 | 16/6/2026 | Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character. | |
| Modificada | Baja (2.1) | 0.67% | — | Info-zip Unzip | 12/7/2001 | 16/6/2026 | Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename. |