Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Info Zip

First CVE: Jul 12, 2001Active for: 25 yearsTotal CVEs: 28

Info Zip maintains widely used compression utilities, particularly the unzip and zip tools, that are embedded across operating systems, servers, and build environments despite a narrowly scoped product portfolio. The vendor's vulnerability exposure, while modest in volume, reflects the parsing complexity inherent to archive-format handling in tools that process untrusted input at scale. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Info Zip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2001
25 years ago
Most Recent CVE
Jan 27, 2020
2,370 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0282LOW
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result i
Jun 16, 20032.633NOYES
CVE-2004-1010HIGH
Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing
Mar 1, 200510.031NONO
CVE-2008-0888HIGH
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) a
Mar 17, 20089.330NONO
CVE-2018-1000034CRITICAL
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
Feb 9, 20189.129NONO
CVE-2018-1000033CRITICAL
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
Feb 9, 20189.129NONO
CVE-2018-13410CRITICAL
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified
Jul 6, 20189.828NONO
CVE-2018-1000031HIGH
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
Feb 9, 20187.826NONO
CVE-2015-1315HIGH
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by
Feb 23, 20157.526NONO
CVE-2018-1000032HIGH
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
Feb 9, 20187.823NONO
CVE-2005-4667LOW
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a
Dec 31, 20053.720NOYES
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
33%
40%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (13.3%)
Network4 (26.7%)
Unknown9 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (40.0%)
High0 (0.0%)
Unknown9 (60.0%)
User Interaction
None4 (26.7%)
Unknown9 (60.0%)
Required2 (13.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (40.0%)
Unknown9 (60.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Info Zip.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Info Zip — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Info Zip's Products

View all 3 CNAs →

Top CWEs