Vulnerabilities > ZSH

DATE CVE VULNERABILITY TITLE RISK
2018-02-27 CVE-2016-10714 Numeric Errors vulnerability in multiple products
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
network
low complexity
zsh canonical CWE-189
7.5
2018-02-27 CVE-2014-10071 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
network
low complexity
zsh canonical CWE-119
7.5
2007-12-04 CVE-2007-6209 Permissions, Privileges, and Access Controls vulnerability in ZSH 4.3.4
Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
linux zsh CWE-264
4.6