Skip to content
Noroxi

zlib records

17 published records for vendor zlib.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
94.1%
Median publish → KEV
No record has entered KEV

All records

17 records
  • zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

    HighCVSS 7.5Proof of conceptEPSS 52%

    zlib · zlibMar 25, 2022

  • zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    zlib · zlibAug 5, 2022

  • The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai

    CriticalCVSS 9.8No exploitEPSS 10%

    zlib · zlibMar 15, 2002

  • inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

    CriticalCVSS 9.8No exploitEPSS 8%

    zlib · zlibMay 23, 2017

  • The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big

    CriticalCVSS 9.8No exploitEPSS 6%

    zlib · zlibMay 23, 2017

  • MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename,

    CriticalCVSS 9.8No exploitEPSS 3%

    zlib · zlibOct 13, 2023

  • CVE-2003-0107
    38Monitor

    Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnp

    HighCVSS 7.5Proof of conceptEPSS 26%

    zlib · zlibMar 7, 2003

  • CVE-2016-9842
    37Monitor

    The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving

    HighCVSS 8.8No exploitEPSS 5%

    zlib · zlibMay 23, 2017

  • CVE-2016-9840
    36Monitor

    inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

    HighCVSS 8.8No exploitEPSS 5%

    zlib · zlibMay 23, 2017

  • CVE-2005-2096
    32Monitor

    zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete

    HighCVSS 7.5No exploitEPSS 6%

    zlib · zlibJul 6, 2005

  • CVE-2025-0725
    29Monitor

    gzip integer overflow

    HighCVSS 7.3No exploitEPSS 1%

    netapp · hci baseboard management controllerFeb 5, 2025

  • zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that

    MediumCVSS 5.5No exploitEPSS 0%

    zlib · zlibFeb 18, 2026

  • CVE-2005-1849
    21Monitor

    inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dy

    MediumCVSS 5.0No exploitEPSS 4%

    zlib · zlibJul 26, 2005

  • CVE-2015-1191
    21Monitor

    Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2)

    MediumCVSS 5.0No exploitEPSS 3%

    zlib · pigzJan 21, 2015

  • zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()

    MediumCVSS 4.6No exploitEPSS 0%

    zlib · zlibJan 7, 2026

  • CVE-2013-0296
    17Monitor

    Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions t

    MediumCVSS 4.4No exploitEPSS 0%

    zlib · pigzApr 27, 2014

  • The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial o

    LowCVSS 2.1No exploitEPSS 0%

    zlib · zlibOct 20, 2004