Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Info-zip WIZ | 27/1/2020 | 16/6/2026 | Wiz 5.0.3 has a user mode write access violation | |
| Modificada | Crítica (9.8) | 3.8% | — | Info-zip Project ZIP | 6/7/2018 | 18/9/2026 | Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party… | |
| Modificada | Crítica (9.1) | 1.4% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | |
| Modificada | Crítica (9.1) | 1.7% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | |
| Modificada | Alta (7.8) | 1.3% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution. | |
| Modificada | Alta (7.8) | 1.3% | — | Info-zip Unzip | 9/2/2018 | 17/6/2026 | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution. | |
| Modificada | Alta (7.5) | 4.9% | — | Canonical Ubuntu LinuxInfo-zip Unzip | 23/2/2015 | 17/6/2026 | Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8. | |
| Modificada | Baja (3.7) | 1.5% | — | Info-zip Unzip | 31/12/2005 | 16/6/2026 | Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is… | |
| Modificada | Baja (1.2) | 0.40% | — | Info-zip Unzip | 5/8/2005 | 16/6/2026 | Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete. | |
| Modificada | Media (6.2) | 0.40% | — | Info-zip Unzip | 2/5/2005 | 16/6/2026 | Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges. | |
| Modificada | Alta (10) | 9.2% | — | Info-zip ZIP | 1/3/2005 | 16/6/2026 | Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname. | |
| Modificada | Baja (2.6) | 22% | — | Info-zip UnzipSCO Openlinux ServerSCO Openlinux Workstation | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence. | |
| Modificada | Baja (2.1) | 0.50% | — | Info-zip Unzip | 12/7/2001 | 16/6/2026 | Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character. | |
| Modificada | Baja (2.1) | 0.67% | — | Info-zip Unzip | 12/7/2001 | 16/6/2026 | Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename. |