WinZip kayıtları
winzip üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %7,1
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %21,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-255 Credentials Management Errors1
- CWE-693 Protection Mechanism Failure1
- CWE-787 Out-of-bounds Write1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2004-0333Kavram kanıtı | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Kritik10,0 | — | %24,2 | 23 Kas 2004 |
43Planlayın | CVE-2002-0370İstismar yok | Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code vallume systems division · stuffit expander | Yüksek7,5 | — | %43,3 | 10 Eki 2002 |
43Planlayın | CVE-2004-0234İstismar yok | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewaclearswift · mailsweeper · CWE-119 | Kritik10,0 | — | %10,3 | 18 Ağu 2004 |
41Planlayın | CVE-2006-3890Kavram kanıtı | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applicsky software · fileview activex control | Kritik9,3 | — | %14,6 | 21 Kas 2006 |
38İzleyin | CVE-2025-1240İstismar yok | WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilitywinzip · winzip · CWE-787 | Yüksek8,8 | — | %10,3 | 11 Şub 2025 |
38İzleyin | CVE-2006-6884Kavram kanıtı | Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 awinzip · winzip · CWE-119 | Kritik9,3 | — | %4,5 | 31 Ara 2006 |
34İzleyin | CVE-2006-5198Silahlaştırılmış | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remotewinzip · winzip | Orta4,0 | — | %60,4 | 14 Kas 2006 |
31İzleyin | CVE-2008-3442İstismar yok | WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code winzip · winzip · CWE-94 | Yüksek7,5 | — | %3,8 | 1 Ağu 2008 |
31İzleyin | CVE-2024-8811İstismar yok | WinZip Mark-of-the-Web Bypass Vulnerabilitywinzip · winzip · CWE-693 | Yüksek7,8 | — | %0,4 | 22 Kas 2024 |
26İzleyin | CVE-2004-0235İstismar yok | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive clearswift · mailsweeper | Orta6,4 | — | %4,1 | 18 Ağu 2004 |
26İzleyin | CVE-2007-0264Kavram kanıtı | Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitwinzip · winzip | Orta6,6 | — | %0,7 | 16 Oca 2007 |
18İzleyin | CVE-2001-0449İstismar yok | Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail commwinzip · winzip | Orta4,6 | — | %0,4 | 27 Haz 2001 |
18İzleyin | CVE-2003-1376İstismar yok | WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys winzip · winzip · CWE-255 | Orta4,6 | — | %0,2 | 31 Ara 2003 |
14İzleyin | CVE-2004-1465Kavram kanıtı | Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the commanwinzip · winzip | Düşük3,7 | — | %1,1 | 31 Ara 2004 |
- CVE-2004-033347Planlayın
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
KritikCVSS 10,0Kavram kanıtıEPSS %24uudeview · uudeview23 Kas 2004
- CVE-2002-037043Planlayın
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code v
YüksekCVSS 7,5İstismar yokEPSS %43allume systems division · stuffit expander10 Eki 2002
- CVE-2004-023443Planlayın
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewa
KritikCVSS 10,0İstismar yokEPSS %10clearswift · mailsweeper18 Ağu 2004
- CVE-2006-389041Planlayın
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applic
KritikCVSS 9,3Kavram kanıtıEPSS %15sky software · fileview activex control21 Kas 2006
- CVE-2025-124038İzleyin
WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %10winzip · winzip11 Şub 2025
- CVE-2006-688438İzleyin
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 a
KritikCVSS 9,3Kavram kanıtıEPSS %5winzip · winzip31 Ara 2006
- CVE-2006-519834İzleyin
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote
OrtaCVSS 4,0SilahlaştırılmışEPSS %60winzip · winzip14 Kas 2006
- CVE-2008-344231İzleyin
WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code
YüksekCVSS 7,5İstismar yokEPSS %4winzip · winzip1 Ağu 2008
- CVE-2024-881131İzleyin
WinZip Mark-of-the-Web Bypass Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0winzip · winzip22 Kas 2024
- CVE-2004-023526İzleyin
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive
OrtaCVSS 6,4İstismar yokEPSS %4clearswift · mailsweeper18 Ağu 2004
- CVE-2007-026426İzleyin
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbit
OrtaCVSS 6,6Kavram kanıtıEPSS %1winzip · winzip16 Oca 2007
- CVE-2001-044918İzleyin
Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail comm
OrtaCVSS 4,6İstismar yokEPSS %0winzip · winzip27 Haz 2001
- CVE-2003-137618İzleyin
WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys
OrtaCVSS 4,6İstismar yokEPSS %0winzip · winzip31 Ara 2003
- CVE-2004-146514İzleyin
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the comman
DüşükCVSS 3,7Kavram kanıtıEPSS %1winzip · winzip31 Ara 2004