VYPR
Vendor

Libzip

Products
6
CVEs
12
Across products
13
Status
Private

Products

6

Recent CVEs

12
  • CVE-2018-16717CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.

  • CVE-2017-12858CriAug 23, 2017
    risk 0.64cvss 9.8epss 0.03

    Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.

  • CVE-2018-16716CriMay 2, 2019
    risk 0.60cvss 9.1epss 0.09

    A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

  • CVE-2024-24794HigFeb 20, 2024
    risk 0.53cvss 8.1epss 0.01

    A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the…

  • CVE-2024-24793HigFeb 20, 2024
    risk 0.53cvss 8.1epss 0.01

    A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the…

  • CVE-2025-27580HigApr 24, 2025
    risk 0.49cvss 7.5epss 0.01

    NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and…

  • CVE-2017-14107MedSep 1, 2017
    risk 0.43cvss 6.5epss 0.03

    The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.

  • CVE-2018-16718MedMay 2, 2019
    risk 0.40cvss 6.1epss 0.01

    An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

  • CVE-2015-2331Mar 30, 2015
    risk 0.02cvss epss 0.28

    Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application…

  • CVE-2019-17582CriFeb 9, 2021
    risk 0.00cvss 9.8epss 0.02

    A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer states "This use-after-free is triggered prior to the double free reported in…

  • CVE-2012-1163Jul 12, 2012
    risk 0.00cvss epss 0.03

    Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a…

  • CVE-2012-1162Jul 12, 2012
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect…