Search CVE reports


Toggle filters

61 – 70 of 171 results


CVE-2022-24615

Low priority
Needs evaluation

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use...

1 affected package

zip4j

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zip4j Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2022-0530

Low priority

Some fixes available 5 of 6

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading...

1 affected package

unzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unzip — — Fixed Fixed Fixed
Show less packages

CVE-2022-0529

Medium priority

Some fixes available 5 of 6

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading...

1 affected package

unzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unzip — — Fixed Fixed Fixed
Show less packages

CVE-2021-23413

Low priority
Needs evaluation

This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.

1 affected package

node-jszip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-jszip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-18442

Low priority

Some fixes available 3 of 7

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

1 affected package

zziplib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zziplib — — Not affected Fixed Fixed
Show less packages

CVE-2021-27347

Medium priority

Some fixes available 2 of 6

Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted compressed file.

1 affected package

lrzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lrzip Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-27345

Low priority

Some fixes available 2 of 6

A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.

1 affected package

lrzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lrzip Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-25467

Low priority

Some fixes available 4 of 14

A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.

1 affected package

lrzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lrzip Needs evaluation Needs evaluation Not affected Fixed Fixed
Show less packages

CVE-2021-3465

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

p7zip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
p7zip — — — Ignored Ignored
Show less packages

CVE-2019-17582

Medium priority
Ignored

A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecified impact by attempting to unzip a malformed ZIP archive. NOTE: the discoverer states "This use-after-free is...

1 affected package

libzip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libzip — — Not affected Not affected Not affected
Show less packages