VYPR

Zip

by Info Zip

Source repositories

CVEs (2)

  • CVE-2018-13410CriJul 6, 2018
    risk 0.64cvss 9.8epss 0.04

    Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic…

  • CVE-2004-1010Mar 1, 2005
    risk 0.01cvss epss 0.09

    Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.