Zlib Ng is a high-performance compression library maintained as a community fork of the original zlib, embedded across a wide variety of applications and embedded systems where data compression is required. The vendor's narrow product portfolio, exemplified by minizip_ng, reflects its focused role as a foundational component rather than a standalone application, meaning vulnerabilities here propagate downstream to any software that links the library. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zlib Ng over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48107HIGH Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file. | Nov 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-48106HIGH Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file. | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2014-9485MEDIUM Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files | Jan 16, 2018 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zlib Ng.
Media articles that mention a CVE ID that affects a product developed by Zlib Ng — matched by CVE ID, not by vendor name.