Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zsh

First CVE: Dec 4, 2007Active for: 19 yearsTotal CVEs: 16
47.1
VTI Score
High

Zsh is a widely adopted Unix shell that serves as the interactive command interpreter and scripting engine across numerous systems, making vulnerabilities in this core utility a broadly distributed risk. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, concentrating on memory-safety and privilege-handling weaknesses including buffer overflows, improper bounds checking, and unsafe privilege-dropping logic that are characteristic of native C implementations handling untrusted input. Defenders should treat zsh updates as high-priority across all affected systems; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 94% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zsh over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2007
18 years ago
Most Recent CVE
Feb 14, 2022
1,621 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-13259CRITICAL
An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the
Sep 5, 20189.832NONO
CVE-2018-0502CRITICAL
An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.
Sep 5, 20189.831NONO
CVE-2014-10071CRITICAL
In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
Feb 27, 20189.830NONO
CVE-2018-7548CRITICAL
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
Feb 27, 20189.829NONO
CVE-2017-18206CRITICAL
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
Feb 27, 20189.828NONO
CVE-2016-10714CRITICAL
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Feb 27, 20189.828NONO
CVE-2021-45444HIGH
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive P
Feb 14, 20227.827NONO
CVE-2019-20044HIGH
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges
Feb 24, 20207.826NONO
CVE-2018-1100HIGH
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the
Apr 11, 20187.825NONO
CVE-2014-10072CRITICAL
In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.
Feb 27, 20189.825NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
13%
44%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (37.5%)
Network9 (56.3%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High1 (6.3%)
Unknown1 (6.3%)
User Interaction
None14 (87.5%)
Unknown1 (6.3%)
Required1 (6.3%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None10 (62.5%)
Unknown1 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zsh.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zsh — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zsh's Products

View all 3 CNAs →

Top CWEs