Zint is a specialized barcode-generation library with a narrow but distributed footprint across point-of-sale, inventory, and document-processing systems. Its vulnerability profile clusters around memory-safety issues—NULL pointer dereferences and out-of-bounds read and write conditions—typical of a C-based encoding engine that parses and renders diverse barcode formats. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zint over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27799HIGH ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API through an application that includes the Z | Feb 26, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-9385HIGH A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upcean.c, when called from eanx in upcean.c during EAN barcode | Feb 25, 2020 | 7.5 | 23 | NO | NO |
CVE-2021-39247MEDIUM Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c. | Aug 17, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zint.
Media articles that mention a CVE ID that affects a product developed by Zint — matched by CVE ID, not by vendor name.