zlib records
17 published records for vendor zlib.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 94.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write3
- CWE-1284 Improper Validation of Specified Quantity in Input1
- CWE-1335 Incorrect Bitwise Shift of Integer1
- CWE-190 Integer Overflow or Wraparound1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2018-25032Proof of concept | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib · zlib · CWE-787 | High7.5 | — | 51.7% | Mar 25, 2022 |
45Plan | CVE-2022-37434Proof of concept | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.zlib · zlib · CWE-787 | Critical9.8 | — | 19.0% | Aug 5, 2022 |
42Plan | CVE-2002-0059No exploit | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certaizlib · zlib · CWE-415 | Critical9.8 | — | 9.7% | Mar 15, 2002 |
41Plan | CVE-2016-9841No exploit | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.zlib · zlib | Critical9.8 | — | 7.6% | May 23, 2017 |
41Plan | CVE-2016-9843No exploit | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving bigzlib · zlib | Critical9.8 | — | 5.8% | May 23, 2017 |
40Plan | CVE-2023-45853No exploit | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename,zlib · zlib · CWE-190 | Critical9.8 | — | 3.2% | Oct 13, 2023 |
38Monitor | CVE-2003-0107Proof of concept | Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnpzlib · zlib | High7.5 | — | 26.0% | Mar 7, 2003 |
37Monitor | CVE-2016-9842No exploit | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involvingzlib · zlib · CWE-1335 | High8.8 | — | 5.2% | May 23, 2017 |
36Monitor | CVE-2016-9840No exploit | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.zlib · zlib | High8.8 | — | 4.8% | May 23, 2017 |
32Monitor | CVE-2005-2096No exploit | zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete zlib · zlib | High7.5 | — | 5.6% | Jul 6, 2005 |
29Monitor | CVE-2025-0725No exploit | gzip integer overflownetapp · hci baseboard management controller · CWE-120 | High7.3 | — | 1.3% | Feb 5, 2025 |
22Monitor | CVE-2026-27171No exploit | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that zlib · zlib · CWE-1284 | Medium5.5 | — | 0.2% | Feb 18, 2026 |
21Monitor | CVE-2005-1849No exploit | inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dyzlib · zlib | Medium5.0 | — | 4.1% | Jul 26, 2005 |
21Monitor | CVE-2015-1191No exploit | Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2)zlib · pigz · CWE-22 | Medium5.0 | — | 3.0% | Jan 21, 2015 |
18Monitor | CVE-2026-22184No exploit | zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()zlib · zlib · CWE-787 | Medium4.6 | — | 0.4% | Jan 7, 2026 |
17Monitor | CVE-2013-0296No exploit | Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions tzlib · pigz · CWE-264 | Medium4.4 | — | 0.3% | Apr 27, 2014 |
8Monitor | CVE-2004-0797No exploit | The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial ozlib · zlib | Low2.1 | — | 0.5% | Oct 20, 2004 |
- CVE-2018-2503246Plan
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
HighCVSS 7.5Proof of conceptEPSS 52%zlib · zlibMar 25, 2022
- CVE-2022-3743445Plan
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
CriticalCVSS 9.8Proof of conceptEPSS 19%zlib · zlibAug 5, 2022
- CVE-2002-005942Plan
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai
CriticalCVSS 9.8No exploitEPSS 10%zlib · zlibMar 15, 2002
- CVE-2016-984141Plan
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CriticalCVSS 9.8No exploitEPSS 8%zlib · zlibMay 23, 2017
- CVE-2016-984341Plan
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big
CriticalCVSS 9.8No exploitEPSS 6%zlib · zlibMay 23, 2017
- CVE-2023-4585340Plan
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename,
CriticalCVSS 9.8No exploitEPSS 3%zlib · zlibOct 13, 2023
- CVE-2003-010738Monitor
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnp
HighCVSS 7.5Proof of conceptEPSS 26%zlib · zlibMar 7, 2003
- CVE-2016-984237Monitor
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving
HighCVSS 8.8No exploitEPSS 5%zlib · zlibMay 23, 2017
- CVE-2016-984036Monitor
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
HighCVSS 8.8No exploitEPSS 5%zlib · zlibMay 23, 2017
- CVE-2005-209632Monitor
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete
HighCVSS 7.5No exploitEPSS 6%zlib · zlibJul 6, 2005
- CVE-2025-072529Monitor
gzip integer overflow
HighCVSS 7.3No exploitEPSS 1%netapp · hci baseboard management controllerFeb 5, 2025
- CVE-2026-2717122Monitor
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that
MediumCVSS 5.5No exploitEPSS 0%zlib · zlibFeb 18, 2026
- CVE-2005-184921Monitor
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dy
MediumCVSS 5.0No exploitEPSS 4%zlib · zlibJul 26, 2005
- CVE-2015-119121Monitor
Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2)
MediumCVSS 5.0No exploitEPSS 3%zlib · pigzJan 21, 2015
- CVE-2026-2218418Monitor
zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
MediumCVSS 4.6No exploitEPSS 0%zlib · zlibJan 7, 2026
- CVE-2013-029617Monitor
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions t
MediumCVSS 4.4No exploitEPSS 0%zlib · pigzApr 27, 2014
- CVE-2004-07978Monitor
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial o
LowCVSS 2.1No exploitEPSS 0%zlib · zlibOct 20, 2004