Skip to content
Noroxi

WinZip records

14 published records for vendor winzip.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 7.1%
Pre-auth RCE
8
With a fix record
21.4%
Median publish → KEV
No record has entered KEV

All records

14 records
  • Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers

    CriticalCVSS 10.0Proof of conceptEPSS 24%

    uudeview · uudeviewNov 23, 2004

  • Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code v

    HighCVSS 7.5No exploitEPSS 43%

    allume systems division · stuffit expanderOct 10, 2002

  • Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewa

    CriticalCVSS 10.0No exploitEPSS 10%

    clearswift · mailsweeperAug 18, 2004

  • Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applic

    CriticalCVSS 9.3Proof of conceptEPSS 15%

    sky software · fileview activex controlNov 21, 2006

  • CVE-2025-1240
    38Monitor

    WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 10%

    winzip · winzipFeb 11, 2025

  • CVE-2006-6884
    38Monitor

    Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 a

    CriticalCVSS 9.3Proof of conceptEPSS 5%

    winzip · winzipDec 31, 2006

  • CVE-2006-5198
    34Monitor

    The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote

    MediumCVSS 4.0WeaponizedEPSS 60%

    winzip · winzipNov 14, 2006

  • CVE-2008-3442
    31Monitor

    WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code

    HighCVSS 7.5No exploitEPSS 4%

    winzip · winzipAug 1, 2008

  • CVE-2024-8811
    31Monitor

    WinZip Mark-of-the-Web Bypass Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    winzip · winzipNov 22, 2024

  • CVE-2004-0235
    26Monitor

    Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive

    MediumCVSS 6.4No exploitEPSS 4%

    clearswift · mailsweeperAug 18, 2004

  • CVE-2007-0264
    26Monitor

    Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbit

    MediumCVSS 6.6Proof of conceptEPSS 1%

    winzip · winzipJan 16, 2007

  • CVE-2001-0449
    18Monitor

    Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail comm

    MediumCVSS 4.6No exploitEPSS 0%

    winzip · winzipJun 27, 2001

  • CVE-2003-1376
    18Monitor

    WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys

    MediumCVSS 4.6No exploitEPSS 0%

    winzip · winzipDec 31, 2003

  • CVE-2004-1465
    14Monitor

    Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the comman

    LowCVSS 3.7Proof of conceptEPSS 1%

    winzip · winzipDec 31, 2004