WinZip is a widely deployed file-compression utility with a prominent presence across consumer and enterprise environments, and its vulnerability profile centers on memory-safety and code-injection issues including buffer overflows, out-of-bounds writes, and improper control flow that are typical of legacy native codebases handling untrusted archive formats. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of compression handling as an attack vector for malware distribution and privilege escalation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winzip over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5198MEDIUM The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via | Nov 14, 2006 | 4.0 | 60 | NO | YES |
CVE-2004-0333HIGH Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME ar | Nov 23, 2004 | 10.0 | 48 | NO | YES |
CVE-2002-0370HIGH Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with lon | Oct 10, 2002 | 7.5 | 43 | NO | NO |
CVE-2006-3890HIGH Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execu | Nov 21, 2006 | 9.3 | 40 | NO | YES |
CVE-2025-1240HIGH WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wi | Feb 11, 2025 | 8.8 | 35 | NO | NO |
CVE-2006-6884HIGH Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitr | Dec 31, 2006 | 9.3 | 34 | NO | YES |
CVE-2004-0234HIGH Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local user | Aug 18, 2004 | 10.0 | 29 | NO | NO |
CVE-2007-0264MEDIUM Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argume | Jan 16, 2007 | 6.6 | 27 | NO | YES |
CVE-2024-8811HIGH WinZip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User | Nov 22, 2024 | 7.8 | 25 | NO | NO |
CVE-2025-33028MEDIUM In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-th | Apr 15, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winzip.
Media articles that mention a CVE ID that affects a product developed by Winzip — matched by CVE ID, not by vendor name.