The Unzip Project maintains a widely embedded file-decompression utility that, despite its narrow product scope, appears in a vast range of systems and applications where ZIP archive handling is required. Vulnerabilities affecting unzip cluster around memory-safety and path-handling weaknesses—including buffer overflows, out-of-bounds writes, path traversal, and NULL-pointer dereferences—that are characteristic of a legacy C codebase operating on untrusted archive formats. A meaningful share of these vulnerabilities reach serious severity, and defenders should treat archive-processing operations as a potential attack surface, particularly where unzip processes untrusted inputs. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unzip Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000035HIGH A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to | Feb 9, 2018 | 7.8 | 40 | NO | NO |
CVE-2008-0888HIGH The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) a | Mar 17, 2008 | 9.3 | 30 | NO | NO |
CVE-2020-36561CRITICAL Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | Dec 27, 2022 | 9.1 | 28 | NO | NO |
CVE-2014-8141HIGH Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command | Jan 31, 2020 | 7.8 | 22 | NO | NO |
CVE-2014-8140HIGH Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t comman | Jan 31, 2020 | 7.8 | 22 | NO | NO |
CVE-2014-8139HIGH Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command ar | Jan 31, 2020 | 7.8 | 22 | NO | NO |
CVE-2018-18384MEDIUM Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffe | Oct 16, 2018 | 5.5 | 21 | NO | NO |
CVE-2015-7696MEDIUM Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted passwor | Nov 6, 2015 | 6.8 | 20 | NO | NO |
CVE-2014-9636MEDIUM unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed fiel | Feb 6, 2015 | 5.0 | 19 | NO | NO |
CVE-2022-0530MEDIUM A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacke | Feb 9, 2022 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unzip Project.
Media articles that mention a CVE ID that affects a product developed by Unzip Project — matched by CVE ID, not by vendor name.