← Back

Zlib

zlib

16 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Zlib
zlib
Pigz
pigz

CVEs (16)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zlib
1Zlib
Jun 17, 2026
Feb 18, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
1Zlib
1Zlib
Jul 15, 2026
Jan 7, 2026
4.6 MEDIUM· v4
7.8 HIGH· v3
N/A· v2
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the co...Show more
zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.Show less
2Smihica
Zlib
2Pyminizip
Zlib
Jul 14, 2026
Oct 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib prod...Show more
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.Show less
6Apple
DebianFedoraproject+3 more
18Active Iq Unified Manager
Debian LinuxFedora+15 more
Jul 14, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applicati...Show more
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).Show less
11Apple
AzulDebian+8 more
27Active Iq Unified Manager
Debian LinuxE Series Santricity Os Controller+24 more
Jul 14, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
10Apple
CanonicalDebian+7 more
24Active Iq Unified Manager
Database ServerDebian Linux+21 more
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
8Apple
CanonicalDebian+5 more
19Database Server
Debian LinuxEnterprise Linux Desktop+16 more
Jul 14, 2026
May 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
9Apple
CanonicalDebian+6 more
39Active Iq Unified Manager
Cloud BackupDatabase Server+36 more
Jul 14, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
9Apple
BoostCanonical+6 more
20Boost
Database ServerDebian Linux+17 more
Jul 14, 2026
May 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
1Zlib
1Pigz
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
1Zlib
1Pigz
May 6, 2026
Apr 27, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass inte...Show more
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.Show less
1Zlib
1Zlib
Apr 16, 2026
Jul 26, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.
1Zlib
1Zlib
Jul 14, 2026
Jul 6, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, a...Show more
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.Show less
1Zlib
1Zlib
Apr 16, 2026
Oct 20, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).
1Zlib
1Zlib
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitra...Show more
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.Show less
1Zlib
1Zlib
Apr 16, 2026
Mar 15, 2002
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote atta...Show more
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.Show less