CVE-2016-9843
- EPSS 5.77%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
- EPSS 4.08%
- Veröffentlicht 26.07.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:47
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.
CVE-2005-2096
- EPSS 5.58%
- Veröffentlicht 06.07.2005 04:00:00
- Zuletzt bearbeitet 14.07.2026 12:16:44
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted...
CVE-2004-0797
- EPSS 0.47%
- Veröffentlicht 20.10.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:06:23
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).
CVE-2003-0107
- EPSS 25.99%
- Veröffentlicht 07.03.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:01:32
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.
CVE-2002-0059
- EPSS 9.69%
- Veröffentlicht 15.03.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:56:40
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary cod...