VYPR

Pkzip

by Pkware

CVEs (2)

  • CVE-2010-5274Sep 7, 2012
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in PKZIP before 12.50.0014 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .zip file. NOTE: some of these details are obtained from…

  • CVE-2001-1270Jul 12, 2001
    risk 0.00cvss epss 0.00

    Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.