zlib kayıtları
zlib üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %94,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write3
- CWE-1284 Improper Validation of Specified Quantity in Input1
- CWE-1335 Incorrect Bitwise Shift of Integer1
- CWE-190 Integer Overflow or Wraparound1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2018-25032Kavram kanıtı | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib · zlib · CWE-787 | Yüksek7,5 | — | %51,7 | 25 Mar 2022 |
44Planlayın | CVE-2022-37434Kavram kanıtı | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.zlib · zlib · CWE-787 | Kritik9,8 | — | %17,9 | 5 Ağu 2022 |
42Planlayın | CVE-2002-0059İstismar yok | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certaizlib · zlib · CWE-415 | Kritik9,8 | — | %9,7 | 15 Mar 2002 |
41Planlayın | CVE-2016-9841İstismar yok | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.zlib · zlib | Kritik9,8 | — | %7,6 | 23 May 2017 |
41Planlayın | CVE-2016-9843İstismar yok | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving bigzlib · zlib | Kritik9,8 | — | %5,8 | 23 May 2017 |
40Planlayın | CVE-2023-45853İstismar yok | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename,zlib · zlib · CWE-190 | Kritik9,8 | — | %3,2 | 13 Eki 2023 |
38İzleyin | CVE-2003-0107Kavram kanıtı | Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnpzlib · zlib | Yüksek7,5 | — | %26,0 | 7 Mar 2003 |
37İzleyin | CVE-2016-9842İstismar yok | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involvingzlib · zlib · CWE-1335 | Yüksek8,8 | — | %5,2 | 23 May 2017 |
36İzleyin | CVE-2016-9840İstismar yok | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.zlib · zlib | Yüksek8,8 | — | %4,8 | 23 May 2017 |
32İzleyin | CVE-2005-2096İstismar yok | zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete zlib · zlib | Yüksek7,5 | — | %5,6 | 6 Tem 2005 |
29İzleyin | CVE-2025-0725İstismar yok | gzip integer overflownetapp · hci baseboard management controller · CWE-120 | Yüksek7,3 | — | %1,3 | 5 Şub 2025 |
22İzleyin | CVE-2026-27171İstismar yok | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that zlib · zlib · CWE-1284 | Orta5,5 | — | %0,2 | 18 Şub 2026 |
21İzleyin | CVE-2005-1849İstismar yok | inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dyzlib · zlib | Orta5,0 | — | %4,1 | 26 Tem 2005 |
21İzleyin | CVE-2015-1191İstismar yok | Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2)zlib · pigz · CWE-22 | Orta5,0 | — | %3,0 | 21 Oca 2015 |
18İzleyin | CVE-2026-22184İstismar yok | zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()zlib · zlib · CWE-787 | Orta4,6 | — | %0,4 | 7 Oca 2026 |
17İzleyin | CVE-2013-0296İstismar yok | Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions tzlib · pigz · CWE-264 | Orta4,4 | — | %0,3 | 27 Nis 2014 |
8İzleyin | CVE-2004-0797İstismar yok | The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial ozlib · zlib | Düşük2,1 | — | %0,5 | 20 Eki 2004 |
- CVE-2018-2503246Planlayın
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
YüksekCVSS 7,5Kavram kanıtıEPSS %52zlib · zlib25 Mar 2022
- CVE-2022-3743444Planlayın
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
KritikCVSS 9,8Kavram kanıtıEPSS %18zlib · zlib5 Ağu 2022
- CVE-2002-005942Planlayın
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai
KritikCVSS 9,8İstismar yokEPSS %10zlib · zlib15 Mar 2002
- CVE-2016-984141Planlayın
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
KritikCVSS 9,8İstismar yokEPSS %8zlib · zlib23 May 2017
- CVE-2016-984341Planlayın
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big
KritikCVSS 9,8İstismar yokEPSS %6zlib · zlib23 May 2017
- CVE-2023-4585340Planlayın
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename,
KritikCVSS 9,8İstismar yokEPSS %3zlib · zlib13 Eki 2023
- CVE-2003-010738İzleyin
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnp
YüksekCVSS 7,5Kavram kanıtıEPSS %26zlib · zlib7 Mar 2003
- CVE-2016-984237İzleyin
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving
YüksekCVSS 8,8İstismar yokEPSS %5zlib · zlib23 May 2017
- CVE-2016-984036İzleyin
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
YüksekCVSS 8,8İstismar yokEPSS %5zlib · zlib23 May 2017
- CVE-2005-209632İzleyin
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete
YüksekCVSS 7,5İstismar yokEPSS %6zlib · zlib6 Tem 2005
- CVE-2025-072529İzleyin
gzip integer overflow
YüksekCVSS 7,3İstismar yokEPSS %1netapp · hci baseboard management controller5 Şub 2025
- CVE-2026-2717122İzleyin
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that
OrtaCVSS 5,5İstismar yokEPSS %0zlib · zlib18 Şub 2026
- CVE-2005-184921İzleyin
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dy
OrtaCVSS 5,0İstismar yokEPSS %4zlib · zlib26 Tem 2005
- CVE-2015-119121İzleyin
Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2)
OrtaCVSS 5,0İstismar yokEPSS %3zlib · pigz21 Oca 2015
- CVE-2026-2218418İzleyin
zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
OrtaCVSS 4,6İstismar yokEPSS %0zlib · zlib7 Oca 2026
- CVE-2013-029617İzleyin
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions t
OrtaCVSS 4,4İstismar yokEPSS %0zlib · pigz27 Nis 2014
- CVE-2004-07978İzleyin
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial o
DüşükCVSS 2,1İstismar yokEPSS %0zlib · zlib20 Eki 2004