VYPR

Minizip Ng

by Zlib Ng

CVEs (3)

  • CVE-2023-48107HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file.

  • CVE-2023-48106HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.

  • CVE-2014-9485MedJan 16, 2018
    risk 0.36cvss 5.5epss 0.04

    Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.