Winace is a file-compression utility with a narrow product portfolio centered on its core archive-handling applications, WinACE and UnACE, which process untrusted archive data from external sources. The recurring vulnerability pattern involves memory-buffer handling weaknesses characteristic of native-code compression tools that parse variable-length archive formats, and the vendor's disclosures frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winace over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2856HIGH Stack-based buffer overflow in the WinACE UNACEV2.DLL third-party compression utility before 2.6.0.0, as used in multiple products including (1) ALZip 5.51 through 6.11, (2) Servan | Sep 8, 2005 | 7.5 | 35 | NO | YES |
CVE-2005-2694HIGH Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that contains an entry with a long f | Aug 26, 2005 | 7.5 | 29 | NO | YES |
CVE-2007-6563HIGH Heap-based buffer overflow in WinAce 2.65 and earlier, and possibly other versions before 2.69, allows user-assisted remote attackers to execute arbitrary code via a long filename | Dec 28, 2007 | 10.0 | 26 | NO | NO |
CVE-2007-2535HIGH WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | May 9, 2007 | 7.8 | 22 | NO | NO |
CVE-2007-1673HIGH unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry str | May 9, 2007 | 7.8 | 21 | NO | NO |
CVE-2006-0813MEDIUM Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive. | Feb 24, 2006 | 5.1 | 16 | NO | NO |
CVE-2015-2063MEDIUM Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow. | Mar 9, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winace.
Media articles that mention a CVE ID that affects a product developed by Winace — matched by CVE ID, not by vendor name.