Info Zip Project maintains the widely used Zip compression utility, a foundational command-line tool embedded in many operating systems and software distributions. The vendor's disclosed vulnerabilities have centered on the core archive-handling product with limited structural pattern at this volume; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Info Zip Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result i | Jun 16, 2003 | 2.6 | 33 | NO | YES |
CVE-2004-1010HIGH Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing | Mar 1, 2005 | 10.0 | 31 | NO | NO |
CVE-2008-0888HIGH The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) a | Mar 17, 2008 | 9.3 | 30 | NO | NO |
CVE-2018-1000034CRITICAL An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | Feb 9, 2018 | 9.1 | 29 | NO | NO |
CVE-2018-1000033CRITICAL An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | Feb 9, 2018 | 9.1 | 29 | NO | NO |
CVE-2018-13410CRITICAL Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified | Jul 6, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-1000031HIGH A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution. | Feb 9, 2018 | 7.8 | 26 | NO | NO |
CVE-2015-1315HIGH Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by | Feb 23, 2015 | 7.5 | 26 | NO | NO |
CVE-2018-1000032HIGH A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution. | Feb 9, 2018 | 7.8 | 23 | NO | NO |
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a | Dec 31, 2005 | 3.7 | 20 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Info Zip Project.
Media articles that mention a CVE ID that affects a product developed by Info Zip Project — matched by CVE ID, not by vendor name.