← Back

Unzip

unzip

Vendor: Info Zip • 11 CVEs

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Info Zip
1Unzip
Nov 21, 2024
Feb 9, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
1Info Zip
1Unzip
Nov 21, 2024
Feb 9, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
1Info Zip
1Unzip
Nov 21, 2024
Feb 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
1Info Zip
1Unzip
Nov 21, 2024
Feb 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
2Canonical
Info Zip
2Ubuntu Linux
Unzip
May 6, 2026
Feb 23, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
1Info Zip
1Unzip
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
3.7 LOW· v2
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many s...Show more
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.Show less
1Info Zip
1Unzip
Apr 16, 2026
Aug 5, 2005
N/A· v4
N/A· v3
1.2 LOW· v2
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is...Show more
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.Show less
1Info Zip
1Unzip
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
2Info Zip
Sco
3Openlinux Server
Openlinux WorkstationUnzip
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
2.6 LOW· v2
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
1Info Zip
1Unzip
Apr 16, 2026
Jul 12, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.
1Info Zip
1Unzip
Apr 16, 2026
Jul 12, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.