Pkware maintains a focused product line centered on the PKZIP compression and archive utility, which has a long deployment history across enterprise systems and file-handling workflows. The observed vulnerability disclosures for this vendor cluster around general weakness classifications rather than a consistent pattern of specific flaw types, reflecting the relatively narrow scope of its exposure surface. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pkware over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5274MEDIUM Untrusted search path vulnerability in PKZIP before 12.50.0014 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonst | Sep 7, 2012 | 6.9 | 21 | NO | NO |
Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (r | Jul 12, 2001 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pkware.
Media articles that mention a CVE ID that affects a product developed by Pkware — matched by CVE ID, not by vendor name.