CVE-2026-85091
- EPSS 0.44%
- Veröffentlicht 03.09.2026 01:04:44
- Zuletzt bearbeitet 09.09.2026 20:41:07
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf...
CVE-2026-76844
- EPSS 0.37%
- Veröffentlicht 24.08.2026 13:12:01
- Zuletzt bearbeitet 01.10.2026 12:17:16
zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale ...
CVE-2026-27171
- EPSS 0.22%
- Veröffentlicht 18.02.2026 02:36:19
- Zuletzt bearbeitet 25.03.2026 21:27:04
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CVE-2026-22184
- EPSS 0.39%
- Veröffentlicht 07.01.2026 20:25:19
- Zuletzt bearbeitet 01.09.2026 13:18:19
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. T...
CVE-2023-45853
- EPSS 3.18%
- Veröffentlicht 14.10.2023 02:15:09
- Zuletzt bearbeitet 14.07.2026 13:17:02
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0...
CVE-2022-37434
- EPSS 17.85%
- Veröffentlicht 05.08.2022 07:15:07
- Zuletzt bearbeitet 14.07.2026 12:16:47
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib s...
CVE-2018-25032
- EPSS 51.73%
- Veröffentlicht 25.03.2022 09:15:08
- Zuletzt bearbeitet 14.07.2026 12:16:46
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVE-2016-9840
- EPSS 4.79%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 14.07.2026 12:16:45
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2016-9841
- EPSS 7.55%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 14.07.2026 12:16:45
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2016-9842
- EPSS 5.2%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 14.07.2026 12:16:46
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.