Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unzip Project

First CVE: Mar 17, 2008Active for: 18 yearsTotal CVEs: 16
33.0
VTI Score
Medium

The Unzip Project maintains a widely embedded file-decompression utility that, despite its narrow product scope, appears in a vast range of systems and applications where ZIP archive handling is required. Vulnerabilities affecting unzip cluster around memory-safety and path-handling weaknesses—including buffer overflows, out-of-bounds writes, path traversal, and NULL-pointer dereferences—that are characteristic of a legacy C codebase operating on untrusted archive formats. A meaningful share of these vulnerabilities reach serious severity, and defenders should treat archive-processing operations as a potential attack surface, particularly where unzip processes untrusted inputs. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Unzip Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 17, 2008
18 years ago
Most Recent CVE
Dec 27, 2022
1,305 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000035HIGH
A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to
Feb 9, 20187.840NONO
CVE-2008-0888HIGH
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) a
Mar 17, 20089.330NONO
CVE-2020-36561CRITICAL
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
Dec 27, 20229.128NONO
CVE-2014-8141HIGH
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command
Jan 31, 20207.822NONO
CVE-2014-8140HIGH
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t comman
Jan 31, 20207.822NONO
CVE-2014-8139HIGH
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command ar
Jan 31, 20207.822NONO
CVE-2018-18384MEDIUM
Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffe
Oct 16, 20185.521NONO
CVE-2015-7696MEDIUM
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted passwor
Nov 6, 20156.820NONO
CVE-2014-9636MEDIUM
unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed fiel
Feb 6, 20155.019NONO
CVE-2022-0530MEDIUM
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacke
Feb 9, 20225.518NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
13%
50%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local11 (68.8%)
Network1 (6.3%)
Unknown4 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (75.0%)
High0 (0.0%)
Unknown4 (25.0%)
User Interaction
None4 (25.0%)
Unknown4 (25.0%)
Required8 (50.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None11 (68.8%)
Unknown4 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unzip Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unzip Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unzip Project's Products

View all 3 CNAs →

Top CWEs