WinZip records
14 published records for vendor winzip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 7.1%
- Pre-auth RCE
- 8
- With a fix record
- 21.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-255 Credentials Management Errors1
- CWE-693 Protection Mechanism Failure1
- CWE-787 Out-of-bounds Write1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2004-0333Proof of concept | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Critical10.0 | — | 24.2% | Nov 23, 2004 |
43Plan | CVE-2002-0370No exploit | Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code vallume systems division · stuffit expander | High7.5 | — | 43.3% | Oct 10, 2002 |
43Plan | CVE-2004-0234No exploit | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewaclearswift · mailsweeper · CWE-119 | Critical10.0 | — | 10.3% | Aug 18, 2004 |
41Plan | CVE-2006-3890Proof of concept | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applicsky software · fileview activex control | Critical9.3 | — | 14.6% | Nov 21, 2006 |
38Monitor | CVE-2025-1240No exploit | WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilitywinzip · winzip · CWE-787 | High8.8 | — | 10.3% | Feb 11, 2025 |
38Monitor | CVE-2006-6884Proof of concept | Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 awinzip · winzip · CWE-119 | Critical9.3 | — | 4.5% | Dec 31, 2006 |
34Monitor | CVE-2006-5198Weaponized | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remotewinzip · winzip | Medium4.0 | — | 60.4% | Nov 14, 2006 |
31Monitor | CVE-2008-3442No exploit | WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code winzip · winzip · CWE-94 | High7.5 | — | 3.8% | Aug 1, 2008 |
31Monitor | CVE-2024-8811No exploit | WinZip Mark-of-the-Web Bypass Vulnerabilitywinzip · winzip · CWE-693 | High7.8 | — | 0.4% | Nov 22, 2024 |
26Monitor | CVE-2004-0235No exploit | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive clearswift · mailsweeper | Medium6.4 | — | 4.1% | Aug 18, 2004 |
26Monitor | CVE-2007-0264Proof of concept | Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitwinzip · winzip | Medium6.6 | — | 0.7% | Jan 16, 2007 |
18Monitor | CVE-2001-0449No exploit | Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail commwinzip · winzip | Medium4.6 | — | 0.4% | Jun 27, 2001 |
18Monitor | CVE-2003-1376No exploit | WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys winzip · winzip · CWE-255 | Medium4.6 | — | 0.2% | Dec 31, 2003 |
14Monitor | CVE-2004-1465Proof of concept | Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the commanwinzip · winzip | Low3.7 | — | 1.1% | Dec 31, 2004 |
- CVE-2004-033347Plan
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
CriticalCVSS 10.0Proof of conceptEPSS 24%uudeview · uudeviewNov 23, 2004
- CVE-2002-037043Plan
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code v
HighCVSS 7.5No exploitEPSS 43%allume systems division · stuffit expanderOct 10, 2002
- CVE-2004-023443Plan
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewa
CriticalCVSS 10.0No exploitEPSS 10%clearswift · mailsweeperAug 18, 2004
- CVE-2006-389041Plan
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applic
CriticalCVSS 9.3Proof of conceptEPSS 15%sky software · fileview activex controlNov 21, 2006
- CVE-2025-124038Monitor
WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 10%winzip · winzipFeb 11, 2025
- CVE-2006-688438Monitor
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 a
CriticalCVSS 9.3Proof of conceptEPSS 5%winzip · winzipDec 31, 2006
- CVE-2006-519834Monitor
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote
MediumCVSS 4.0WeaponizedEPSS 60%winzip · winzipNov 14, 2006
- CVE-2008-344231Monitor
WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code
HighCVSS 7.5No exploitEPSS 4%winzip · winzipAug 1, 2008
- CVE-2024-881131Monitor
WinZip Mark-of-the-Web Bypass Vulnerability
HighCVSS 7.8No exploitEPSS 0%winzip · winzipNov 22, 2024
- CVE-2004-023526Monitor
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive
MediumCVSS 6.4No exploitEPSS 4%clearswift · mailsweeperAug 18, 2004
- CVE-2007-026426Monitor
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbit
MediumCVSS 6.6Proof of conceptEPSS 1%winzip · winzipJan 16, 2007
- CVE-2001-044918Monitor
Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail comm
MediumCVSS 4.6No exploitEPSS 0%winzip · winzipJun 27, 2001
- CVE-2003-137618Monitor
WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys
MediumCVSS 4.6No exploitEPSS 0%winzip · winzipDec 31, 2003
- CVE-2004-146514Monitor
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the comman
LowCVSS 3.7Proof of conceptEPSS 1%winzip · winzipDec 31, 2004