Записи Info-ZIP
13 опубликованных записей вендора info-zip.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 38,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2004-1010Эксплойта нет | Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute ainfo-zip · zip | Критическая10,0 | — | 9,2 % | 1 мар. 2005 г. |
37Наблюдать | CVE-2018-1000033Эксплойта нет | An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive meminfo-zip · unzip · CWE-125 | Критическая9,1 | — | 1,7 % | 9 февр. 2018 г. |
36Наблюдать | CVE-2018-1000034Эксплойта нет | An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive meminfo-zip · unzip · CWE-125 | Критическая9,1 | — | 1,4 % | 9 февр. 2018 г. |
31Наблюдать | CVE-2015-1315Эксплойта нет | Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code vinfo-zip · unzip · CWE-119 | Высокая7,5 | — | 4,9 % | 23 февр. 2015 г. |
31Наблюдать | CVE-2018-1000031Эксплойта нет | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly info-zip · unzip · CWE-787 | Высокая7,8 | — | 1,3 % | 9 февр. 2018 г. |
31Наблюдать | CVE-2018-1000032Эксплойта нет | A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly info-zip · unzip · CWE-787 | Высокая7,8 | — | 1,3 % | 9 февр. 2018 г. |
30Наблюдать | CVE-2013-5659Эксплойта нет | Wiz 5.0.3 has a user mode write access violationinfo-zip · wiz · CWE-787 | Высокая7,5 | — | 1,3 % | 27 янв. 2020 г. |
24Наблюдать | CVE-2005-0602Эксплойта нет | Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privilegeinfo-zip · unzip | Средняя6,2 | — | 0,4 % | 2 мая 2005 г. |
17Наблюдать | CVE-2003-0282Proof of concept | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two .info-zip · unzip | Низкая2,6 | — | 22,0 % | 16 июн. 2003 г. |
14Наблюдать | CVE-2005-4667Proof of concept | Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argumentinfo-zip · unzip · CWE-119 | Низкая3,7 | — | 1,5 % | 31 дек. 2005 г. |
8Наблюдать | CVE-2001-1268Эксплойта нет | Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extractioninfo-zip · unzip | Низкая2,1 | — | 0,7 % | 12 июл. 2001 г. |
8Наблюдать | CVE-2001-1269Эксплойта нет | Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that beinfo-zip · unzip | Низкая2,1 | — | 0,5 % | 12 июл. 2001 г. |
4Наблюдать | CVE-2005-2475Эксплойта нет | Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being info-zip · unzip | Низкая1,2 | — | 0,4 % | 5 авг. 2005 г. |
- CVE-2004-101043В плане
Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute a
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %info-zip · zip1 мар. 2005 г.
- CVE-2018-100003337Наблюдать
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive mem
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %info-zip · unzip9 февр. 2018 г.
- CVE-2018-100003436Наблюдать
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive mem
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %info-zip · unzip9 февр. 2018 г.
- CVE-2015-131531Наблюдать
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code v
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %info-zip · unzip23 февр. 2015 г.
- CVE-2018-100003131Наблюдать
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %info-zip · unzip9 февр. 2018 г.
- CVE-2018-100003231Наблюдать
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %info-zip · unzip9 февр. 2018 г.
- CVE-2013-565930Наблюдать
Wiz 5.0.3 has a user mode write access violation
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %info-zip · wiz27 янв. 2020 г.
- CVE-2005-060224Наблюдать
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privilege
СредняяCVSS 6,2Эксплойта нетEPSS 0 %info-zip · unzip2 мая 2005 г.
- CVE-2003-028217Наблюдать
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two .
НизкаяCVSS 2,6Proof of conceptEPSS 22 %info-zip · unzip16 июн. 2003 г.
- CVE-2005-466714Наблюдать
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument
НизкаяCVSS 3,7Proof of conceptEPSS 2 %info-zip · unzip31 дек. 2005 г.
- CVE-2001-12688Наблюдать
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %info-zip · unzip12 июл. 2001 г.
- CVE-2001-12698Наблюдать
Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that be
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %info-zip · unzip12 июл. 2001 г.
- CVE-2005-24754Наблюдать
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being
НизкаяCVSS 1,2Эксплойта нетEPSS 0 %info-zip · unzip5 авг. 2005 г.