Gdraheim maintains zziplib, a specialized compression and archive-handling library that processes ZIP file structures across embedded systems and applications. The vulnerability profile centers on memory-safety weakness classes—buffer boundary violations, resource-management failures, NULL-pointer dereferences, and out-of-bounds reads—that arise from parsing untrusted archive data, a context where a single flaw can affect every downstream product that integrates the library. The recurring pattern reflects the hazards inherent to parsing binary formats in C without bounds-safe abstractions; defenders tracking this library should consider it as part of a software supply-chain inventory rather than as an isolated application, since remediation typically depends on how and when downstream consumers rebuild and redistribute. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gdraheim over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16548MEDIUM An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service at | Sep 5, 2018 | 6.5 | 23 | NO | NO |
CVE-2018-6869MEDIUM In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerabi | Feb 9, 2018 | 6.5 | 23 | NO | NO |
CVE-2018-6484MEDIUM In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to c | Feb 1, 2018 | 6.5 | 23 | NO | NO |
CVE-2018-6381MEDIUM In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation fault caused by invalid memory acce | Jan 29, 2018 | 6.5 | 23 | NO | NO |
CVE-2018-7726MEDIUM An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a | Mar 6, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-7725MEDIUM An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, whi | Mar 6, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-6541MEDIUM In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote at | Feb 2, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-6540MEDIUM In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote attackers could leverage this vulne | Feb 2, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-7727MEDIUM An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack. | Mar 6, 2018 | 6.5 | 21 | NO | NO |
CVE-2018-6542MEDIUM In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c | Feb 2, 2018 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gdraheim.
Media articles that mention a CVE ID that affects a product developed by Gdraheim — matched by CVE ID, not by vendor name.