VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Zlib
>
Zlib
> 1.2.5.1
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2023-10-14
CVE-2023-45853
Integer Overflow or Wraparound vulnerability in multiple products
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field.
network
low complexity
zlib
smihica
CWE-190
critical
9.8
9.8
2022-08-05
CVE-2022-37434
Out-of-bounds Write vulnerability in multiple products
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
network
low complexity
zlib
fedoraproject
debian
netapp
apple
stormshield
CWE-787
critical
9.8
9.8
2022-03-25
CVE-2018-25032
Out-of-bounds Write vulnerability in multiple products
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
network
low complexity
nokogiri
zlib
debian
fedoraproject
apple
python
mariadb
netapp
siemens
azul
goto
CWE-787
7.5
7.5
2017-05-23
CVE-2016-9843
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
network
low complexity
zlib
opensuse
debian
canonical
oracle
redhat
apple
netapp
mariadb
nodejs
critical
9.8
9.8
2017-05-23
CVE-2016-9842
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
network
low complexity
zlib
opensuse
debian
canonical
oracle
redhat
apple
nodejs
8.8
8.8
2017-05-23
CVE-2016-9841
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
network
low complexity
zlib
opensuse
debian
canonical
oracle
redhat
apple
netapp
nodejs
critical
9.8
9.8
2017-05-23
CVE-2016-9840
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
network
low complexity
boost
zlib
opensuse
debian
canonical
oracle
redhat
apple
nodejs
8.8
8.8