Записи WinZip
14 опубликованных записей вендора winzip.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 7,1 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 21,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-255 Credentials Management Errors1
- CWE-693 Protection Mechanism Failure1
- CWE-787 Out-of-bounds Write1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2004-0333Proof of concept | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Критическая10,0 | — | 24,2 % | 23 нояб. 2004 г. |
43В плане | CVE-2002-0370Эксплойта нет | Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code vallume systems division · stuffit expander | Высокая7,5 | — | 43,3 % | 10 окт. 2002 г. |
43В плане | CVE-2004-0234Эксплойта нет | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewaclearswift · mailsweeper · CWE-119 | Критическая10,0 | — | 10,3 % | 18 авг. 2004 г. |
41В плане | CVE-2006-3890Proof of concept | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applicsky software · fileview activex control | Критическая9,3 | — | 14,6 % | 21 нояб. 2006 г. |
38Наблюдать | CVE-2025-1240Эксплойта нет | WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilitywinzip · winzip · CWE-787 | Высокая8,8 | — | 10,3 % | 11 февр. 2025 г. |
38Наблюдать | CVE-2006-6884Proof of concept | Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 awinzip · winzip · CWE-119 | Критическая9,3 | — | 4,5 % | 31 дек. 2006 г. |
34Наблюдать | CVE-2006-5198Готовый эксплойт | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remotewinzip · winzip | Средняя4,0 | — | 60,4 % | 14 нояб. 2006 г. |
31Наблюдать | CVE-2008-3442Эксплойта нет | WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code winzip · winzip · CWE-94 | Высокая7,5 | — | 3,8 % | 1 авг. 2008 г. |
31Наблюдать | CVE-2024-8811Эксплойта нет | WinZip Mark-of-the-Web Bypass Vulnerabilitywinzip · winzip · CWE-693 | Высокая7,8 | — | 0,4 % | 22 нояб. 2024 г. |
26Наблюдать | CVE-2004-0235Эксплойта нет | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive clearswift · mailsweeper | Средняя6,4 | — | 4,1 % | 18 авг. 2004 г. |
26Наблюдать | CVE-2007-0264Proof of concept | Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitwinzip · winzip | Средняя6,6 | — | 0,7 % | 16 янв. 2007 г. |
18Наблюдать | CVE-2001-0449Эксплойта нет | Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail commwinzip · winzip | Средняя4,6 | — | 0,4 % | 27 июн. 2001 г. |
18Наблюдать | CVE-2003-1376Эксплойта нет | WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys winzip · winzip · CWE-255 | Средняя4,6 | — | 0,2 % | 31 дек. 2003 г. |
14Наблюдать | CVE-2004-1465Proof of concept | Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the commanwinzip · winzip | Низкая3,7 | — | 1,1 % | 31 дек. 2004 г. |
- CVE-2004-033347В плане
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
КритическаяCVSS 10,0Proof of conceptEPSS 24 %uudeview · uudeview23 нояб. 2004 г.
- CVE-2002-037043В плане
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code v
ВысокаяCVSS 7,5Эксплойта нетEPSS 43 %allume systems division · stuffit expander10 окт. 2002 г.
- CVE-2004-023443В плане
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewa
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %clearswift · mailsweeper18 авг. 2004 г.
- CVE-2006-389041В плане
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applic
КритическаяCVSS 9,3Proof of conceptEPSS 15 %sky software · fileview activex control21 нояб. 2006 г.
- CVE-2025-124038Наблюдать
WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 10 %winzip · winzip11 февр. 2025 г.
- CVE-2006-688438Наблюдать
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 a
КритическаяCVSS 9,3Proof of conceptEPSS 5 %winzip · winzip31 дек. 2006 г.
- CVE-2006-519834Наблюдать
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote
СредняяCVSS 4,0Готовый эксплойтEPSS 60 %winzip · winzip14 нояб. 2006 г.
- CVE-2008-344231Наблюдать
WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %winzip · winzip1 авг. 2008 г.
- CVE-2024-881131Наблюдать
WinZip Mark-of-the-Web Bypass Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %winzip · winzip22 нояб. 2024 г.
- CVE-2004-023526Наблюдать
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive
СредняяCVSS 6,4Эксплойта нетEPSS 4 %clearswift · mailsweeper18 авг. 2004 г.
- CVE-2007-026426Наблюдать
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbit
СредняяCVSS 6,6Proof of conceptEPSS 1 %winzip · winzip16 янв. 2007 г.
- CVE-2001-044918Наблюдать
Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail comm
СредняяCVSS 4,6Эксплойта нетEPSS 0 %winzip · winzip27 июн. 2001 г.
- CVE-2003-137618Наблюдать
WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys
СредняяCVSS 4,6Эксплойта нетEPSS 0 %winzip · winzip31 дек. 2003 г.
- CVE-2004-146514Наблюдать
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the comman
НизкаяCVSS 3,7Proof of conceptEPSS 1 %winzip · winzip31 дек. 2004 г.