Quazip is a C++ library for reading and writing ZIP archives, with vulnerability exposure concentrated in its core product and centered on path-traversal weaknesses that arise from insufficient validation of archive member pathnames. Defenders using this library should validate extracted file paths against a safelist and be aware of the structural risk that untrusted archives may reference paths outside their intended extraction directory; current CVE counts and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quazip Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1002209MEDIUM QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during | Jul 25, 2018 | 5.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quazip Project.
Media articles that mention a CVE ID that affects a product developed by Quazip Project — matched by CVE ID, not by vendor name.