Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.9)0.17%—Peerigon Unzip-crxAIPeerigon Unzip-crx-3AI25/8/202628/9/2026
A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be executed locally. The exploit has been…
AplazadaBaja (1.9)0.17%—Zjonsson Node-unzipperAI27/7/202627/7/2026
A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of…
AplazadaAlta (7.5)0.61%—Perl IO Uncompress UnzipAI27/5/202624/7/2026
IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named…
AplazadaMedia (5.5)0.13%—Perl IO Uncompress UnzipAI27/5/202624/7/2026
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range…
AplazadaCrítica (9.8)0.41%—Archive Unzip BurstAIInfozipAI12/6/202517/6/2026
Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, CVE-2014-8140 and CVE-2014-8141.
AplazadaAlta (8.8)0.47%—Unzip BOTAI2/12/202417/6/2026
unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are executed through subprocess.Popen with shell=True. Attackers can exploit this vulnerability using a crafted archive name, password, or video name. This vulnerability is fixed…
ModificadaMedia (6.5)0.60%—Upunzipper Project Upunzipper10/6/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upunzipper allows Path Traversal, File Manipulation.This issue affects Upunzipper: from n/a through 1.0.0.
ModificadaCrítica (9.1)1.3%—Unzip Project Unzip27/12/202217/6/2026
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
ModificadaCrítica (9.1)1.2%—Go-unzip Project Go-unzip27/12/202217/6/2026
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
ModificadaBaja (3.3)0.62%—Unzip Project UnzipFedoraproject FedoraRedhat Enterprise Linux24/8/202217/6/2026
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
ModificadaMedia (5.5)2.1%—Unzip Project UnzipRedhat Enterprise LinuxFedoraproject FedoraApple MAC OS X+29/2/202217/6/2026
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
ModificadaMedia (5.5)2.4%—Unzip Project UnzipRedhat Enterprise LinuxFedoraproject FedoraDebian Linux9/2/202217/6/2026
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
ModificadaAlta (7.8)7.4%—Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+231/1/202017/6/2026
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
ModificadaAlta (7.8)7.4%—Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+331/1/202017/6/2026
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
ModificadaAlta (7.8)7.4%—Unzip Project UnzipRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+331/1/202017/6/2026
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.
ModificadaBaja (3.3)0.50%—Unzip Project UnzipDebian Linux4/7/201917/6/2026
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
ModificadaMedia (5.5)2.6%—Unzip Project Unzip16/10/201817/6/2026
Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.
ModificadaMedia (5.5)11%—Unzipper Project Unzipper25/7/201817/6/2026
unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaAlta (7.8)30%—Unzip Project Unzip9/2/201817/6/2026
A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.
ModificadaCrítica (9.1)1.4%—Info-zip Unzip9/2/201817/6/2026
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
ModificadaCrítica (9.1)1.7%—Info-zip Unzip9/2/201817/6/2026
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
ModificadaAlta (7.8)1.3%—Info-zip Unzip9/2/201817/6/2026
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
ModificadaAlta (7.8)1.3%—Info-zip Unzip9/2/201817/6/2026
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
ModificadaMedia (4)1.8%—Unzip Project Unzip18/1/201717/6/2026
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.
ModificadaMedia (4)1.5%—Unzip Project Unzip18/1/201717/6/2026
Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.