Gzip is a widely embedded compression utility whose disclosures remain minimal despite its ubiquity across Unix systems, server software, and embedded applications, making its vulnerability footprint historically narrow. The observed weakness classes reflect miscellaneous or placeholder categorizations in available disclosures rather than a distinctive pattern. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gzip over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4335HIGH Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to c | Sep 19, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-4336HIGH Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a writ | Sep 19, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-4337HIGH Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP ar | Sep 19, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-4334MEDIUM Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference | Sep 19, 2006 | 5.0 | 16 | NO | NO |
CVE-2006-4338MEDIUM unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive. | Sep 19, 2006 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gzip.
Media articles that mention a CVE ID that affects a product developed by Gzip — matched by CVE ID, not by vendor name.