Zipgenius is a file-compression utility offering a focused product line centered on archive creation and extraction, presenting a relatively contained attack surface. The observed vulnerabilities cluster around memory-safety issues, particularly improper buffer-boundary restrictions, which are characteristic of file-format parsers handling untrusted compressed streams. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zipgenius over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1597HIGH Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing an entry with a long fil | Apr 29, 2010 | 9.3 | 40 | NO | YES |
CVE-2009-1058HIGH Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file that triggers an SEH overwrite. NOTE: it is possible that t | Mar 24, 2009 | 10.0 | 37 | NO | YES |
CVE-2005-3317HIGH Multiple stack-based buffer overflows in ZipGenius 5.5.1.468 and 6.0.2.1041, and other versions before 6.0.2.1050, allow remote attackers to execute arbitrary code via (1) a ZIP ar | Oct 27, 2005 | 7.5 | 21 | NO | NO |
Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes | May 2, 2005 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zipgenius.
Media articles that mention a CVE ID that affects a product developed by Zipgenius — matched by CVE ID, not by vendor name.