Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Long Range Zip Project

First CVE: May 8, 2017Active for: 9 yearsTotal CVEs: 23
23.9
VTI Score
Low

The Long Range Zip Project maintains a focused compression utility whose vulnerability footprint, while modest in product scope, recurs across a prominent niche of archival and file-handling workloads. Its disclosures cluster around memory-safety and control-flow weaknesses characteristic of native-code compression libraries: use-after-free conditions, NULL-pointer dereferences, buffer-boundary violations, infinite loops, and out-of-bounds reads that reflect the parser complexity and performance-critical design of zip decompression. These classes of flaws in compression tools can propagate broadly through downstream consumers—particularly backup systems, archive processors, and file managers—where malformed archives may be processed with elevated privilege or in automated contexts. Defenders should treat this vendor's patches as relevant to any pipeline that handles untrusted archives and should inventory deployments where the library is embedded; current severity, exploitation activity, and exposure details are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Long Range Zip Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2017
9 years ago
Most Recent CVE
Aug 17, 2023
1,072 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-10685CRITICAL
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (applicat
May 2, 20189.830NONO
CVE-2017-8844HIGH
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly h
May 8, 20177.826NONO
CVE-2021-33453HIGH
An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
Jul 26, 20227.824NONO
CVE-2018-11496MEDIUM
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.
May 26, 20186.523NONO
CVE-2022-26291MEDIUM
lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to
Mar 28, 20225.521NONO
CVE-2018-5786MEDIUM
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to ca
Jan 19, 20185.521NONO
CVE-2018-5747MEDIUM
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of servi
Jan 17, 20185.521NONO
CVE-2018-5650MEDIUM
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to c
Jan 12, 20185.521NONO
CVE-2017-9929MEDIUM
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
Jun 26, 20175.521NONO
CVE-2017-9928MEDIUM
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
Jun 26, 20175.521NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
87%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local21 (91.3%)
Network2 (8.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (4.3%)
Unknown0 (0.0%)
Required22 (95.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None23 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Long Range Zip Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Long Range Zip Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Long Range Zip Project's Products

View all 1 CNAs →

Top CWEs