CVE-2023-45853
- EPSS 0.62%
- Veröffentlicht 14.10.2023 02:15:09
- Zuletzt bearbeitet 20.12.2024 17:41:31
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0...
CVE-2022-37434
- EPSS 92.47%
- Veröffentlicht 05.08.2022 07:15:07
- Zuletzt bearbeitet 30.05.2025 20:15:30
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib s...
CVE-2018-25032
- EPSS 0.09%
- Veröffentlicht 25.03.2022 09:15:08
- Zuletzt bearbeitet 21.08.2025 20:37:11
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVE-2016-9840
- EPSS 13%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2016-9841
- EPSS 20.28%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2016-9842
- EPSS 10.91%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 04.12.2025 17:15:51
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
CVE-2016-9843
- EPSS 6.98%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
- EPSS 9.93%
- Veröffentlicht 26.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.
CVE-2005-2096
- EPSS 46.48%
- Veröffentlicht 06.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted...
CVE-2004-0797
- EPSS 0.76%
- Veröffentlicht 20.10.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).