Unzip Project
Unzip Project Unzip: vulnerabilidades y CVE
Unzip Project Unzip tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-36561 | Crítica (9.1) | 1.3% | — | 27 dic 2022 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. |
| CVE-2021-4217 | Baja (3.3) | 0.62% | — | 24 ago 2022 | A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading… |
| CVE-2022-0530 | Media (5.5) | 2.1% | — | 9 feb 2022 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip… |
| CVE-2022-0529 | Media (5.5) | 2.4% | — | 9 feb 2022 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip… |
| CVE-2014-8141 | Alta (7.8) | 7.4% | — | 31 ene 2020 | Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. |
| CVE-2014-8140 | Alta (7.8) | 7.4% | — | 31 ene 2020 | Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. |
| CVE-2014-8139 | Alta (7.8) | 7.4% | — | 31 ene 2020 | Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. |
| CVE-2019-13232 | Baja (3.3) | 0.50% | — | 4 jul 2019 | Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue. |
| CVE-2018-18384 | Media (5.5) | 2.6% | — | 16 oct 2018 | Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12. |
| CVE-2018-1000035 | Alta (7.8) | 30% | — | 9 feb 2018 | A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution. |
| CVE-2016-9844 | Media (4) | 1.8% | — | 18 ene 2017 | Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header. |
| CVE-2014-9913 | Media (4) | 1.5% | — | 18 ene 2017 | Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method. |
| CVE-2015-7697 | Media (4.3) | 6.1% | — | 6 nov 2015 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive. |
| CVE-2015-7696 | Media (6.8) | 7.2% | — | 6 nov 2015 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly… |
| CVE-2014-9636 | Media (5) | 12% | — | 6 feb 2015 | unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises… |
| CVE-2008-0888 | Alta (9.3) | 6.3% | — | 17 mar 2008 | The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via… |