Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Winzip

First CVE: Jun 27, 2001Active for: 25 yearsTotal CVEs: 15
47.8
VTI Score
High

WinZip is a widely deployed file-compression utility with a prominent presence across consumer and enterprise environments, and its vulnerability profile centers on memory-safety and code-injection issues including buffer overflows, out-of-bounds writes, and improper control flow that are typical of legacy native codebases handling untrusted archive formats. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of compression handling as an attack vector for malware distribution and privilege escalation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Winzip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2001
25 years ago
Most Recent CVE
Apr 15, 2025
465 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-5198MEDIUM
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via
Nov 14, 20064.060NOYES
CVE-2004-0333HIGH
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME ar
Nov 23, 200410.048NOYES
CVE-2002-0370HIGH
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with lon
Oct 10, 20027.543NONO
CVE-2006-3890HIGH
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execu
Nov 21, 20069.340NOYES
CVE-2025-1240HIGH
WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wi
Feb 11, 20258.835NONO
CVE-2006-6884HIGH
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitr
Dec 31, 20069.334NOYES
CVE-2004-0234HIGH
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local user
Aug 18, 200410.029NONO
CVE-2007-0264MEDIUM
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argume
Jan 16, 20076.627NOYES
CVE-2024-8811HIGH
WinZip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User
Nov 22, 20247.825NONO
CVE-2025-33028MEDIUM
In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-th
Apr 15, 20256.121NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
40%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (6.7%)
Network2 (13.3%)
Unknown12 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (20.0%)
High0 (0.0%)
Unknown12 (80.0%)
User Interaction
None0 (0.0%)
Unknown12 (80.0%)
Required3 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (20.0%)
Unknown12 (80.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
40.0% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Winzip.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Winzip — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Winzip's Products

View all 3 CNAs →

Top CWEs