libzip records
3 published records for vendor libzip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-415 Double Free1
- CWE-416 Use After Free1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-12858No exploit | Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknownlibzip · libzip · CWE-415 | Critical9.8 | — | 3.3% | Aug 23, 2017 |
40Plan | CVE-2019-17582No exploit | A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attemptilibzip · libzip · CWE-416 | Critical9.8 | — | 2.5% | Feb 9, 2021 |
27Monitor | CVE-2017-14107No exploit | The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial libzip · libzip · CWE-770 | Medium6.5 | — | 3.2% | Sep 1, 2017 |
- CVE-2017-1285840Plan
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown
CriticalCVSS 9.8No exploitEPSS 3%libzip · libzipAug 23, 2017
- CVE-2019-1758240Plan
A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempti
CriticalCVSS 9.8No exploitEPSS 2%libzip · libzipFeb 9, 2021
- CVE-2017-1410727Monitor
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial
MediumCVSS 6.5No exploitEPSS 3%libzip · libzipSep 1, 2017