İçeriğe atla
Noroxi

zlib kayıtları

zlib üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%94,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

17 kayıt
  • CVE-2018-25032
    46Planlayın

    zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

    YüksekCVSS 7,5Kavram kanıtıEPSS %52

    zlib · zlib25 Mar 2022

  • CVE-2022-37434
    44Planlayın

    zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.

    KritikCVSS 9,8Kavram kanıtıEPSS %18

    zlib · zlib5 Ağu 2022

  • CVE-2002-0059
    42Planlayın

    The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai

    KritikCVSS 9,8İstismar yokEPSS %10

    zlib · zlib15 Mar 2002

  • CVE-2016-9841
    41Planlayın

    inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

    KritikCVSS 9,8İstismar yokEPSS %8

    zlib · zlib23 May 2017

  • CVE-2016-9843
    41Planlayın

    The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big

    KritikCVSS 9,8İstismar yokEPSS %6

    zlib · zlib23 May 2017

  • CVE-2023-45853
    40Planlayın

    MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename,

    KritikCVSS 9,8İstismar yokEPSS %3

    zlib · zlib13 Eki 2023

  • CVE-2003-0107
    38İzleyin

    Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnp

    YüksekCVSS 7,5Kavram kanıtıEPSS %26

    zlib · zlib7 Mar 2003

  • CVE-2016-9842
    37İzleyin

    The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving

    YüksekCVSS 8,8İstismar yokEPSS %5

    zlib · zlib23 May 2017

  • CVE-2016-9840
    36İzleyin

    inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

    YüksekCVSS 8,8İstismar yokEPSS %5

    zlib · zlib23 May 2017

  • CVE-2005-2096
    32İzleyin

    zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete

    YüksekCVSS 7,5İstismar yokEPSS %6

    zlib · zlib6 Tem 2005

  • CVE-2025-0725
    29İzleyin

    gzip integer overflow

    YüksekCVSS 7,3İstismar yokEPSS %1

    netapp · hci baseboard management controller5 Şub 2025

  • CVE-2026-27171
    22İzleyin

    zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that

    OrtaCVSS 5,5İstismar yokEPSS %0

    zlib · zlib18 Şub 2026

  • CVE-2005-1849
    21İzleyin

    inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dy

    OrtaCVSS 5,0İstismar yokEPSS %4

    zlib · zlib26 Tem 2005

  • CVE-2015-1191
    21İzleyin

    Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2)

    OrtaCVSS 5,0İstismar yokEPSS %3

    zlib · pigz21 Oca 2015

  • CVE-2026-22184
    18İzleyin

    zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()

    OrtaCVSS 4,6İstismar yokEPSS %0

    zlib · zlib7 Oca 2026

  • CVE-2013-0296
    17İzleyin

    Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions t

    OrtaCVSS 4,4İstismar yokEPSS %0

    zlib · pigz27 Nis 2014

  • CVE-2004-0797
    8İzleyin

    The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial o

    DüşükCVSS 2,1İstismar yokEPSS %0

    zlib · zlib20 Eki 2004