Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zsh Project

First CVE: Dec 4, 2007Active for: 19 yearsTotal CVEs: 16

Zsh is a widely used Unix shell that appears as a standard component across many Linux distributions and systems, giving its codebase a broad implicit footprint despite a narrowly scoped product line. The observed vulnerabilities center on memory-safety issues, particularly improper buffer restrictions and NULL-pointer dereferences, which are characteristic of parser-intensive native code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 72% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zsh Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2007
18 years ago
Most Recent CVE
Feb 14, 2022
1,621 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-13259CRITICAL
An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the
Sep 5, 20189.832NONO
CVE-2018-0502CRITICAL
An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.
Sep 5, 20189.831NONO
CVE-2014-10071CRITICAL
In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
Feb 27, 20189.830NONO
CVE-2018-7548CRITICAL
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
Feb 27, 20189.829NONO
CVE-2017-18206CRITICAL
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
Feb 27, 20189.828NONO
CVE-2016-10714CRITICAL
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
Feb 27, 20189.828NONO
CVE-2021-45444HIGH
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive P
Feb 14, 20227.827NONO
CVE-2019-20044HIGH
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges
Feb 24, 20207.826NONO
CVE-2018-1100HIGH
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the
Apr 11, 20187.825NONO
CVE-2014-10072CRITICAL
In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.
Feb 27, 20189.825NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
13%
44%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (37.5%)
Network9 (56.3%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High1 (6.3%)
Unknown1 (6.3%)
User Interaction
None14 (87.5%)
Unknown1 (6.3%)
Required1 (6.3%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None10 (62.5%)
Unknown1 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zsh Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zsh Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zsh Project's Products

View all 3 CNAs →

Top CWEs