Known Vulnerabilities for Unzip by Unzip Project
Listed below are 10 of the newest known vulnerabilities associated with "Unzip" by "Unzip Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-70952 | pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zi... | Not Provided | 2026-03-25 | 2026-03-28 |
| CVE-2022-0530 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a ... | 5.5 - MEDIUM | 2022-02-09 | 2023-11-09 |
| CVE-2022-0529 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a ... | 5.5 - MEDIUM | 2022-02-09 | 2023-11-09 |
| CVE-2019-13232 | Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consump... | 3.3 - LOW | 2019-07-04 | 2023-11-07 |
| CVE-2018-1000035 | A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that a... | 7.8 - HIGH | 2018-02-09 | 2020-08-24 |
| CVE-2018-18384 | Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size... | 5.5 - MEDIUM | 2018-10-16 | 2019-12-16 |
| CVE-2016-9844 | Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of serv... | 4 - MEDIUM | 2017-01-18 | 2019-12-16 |
| CVE-2015-7697 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive... | 4.3 - MEDIUM | 2015-11-06 | 2019-12-16 |
| CVE-2015-7696 | Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) o... | 6.8 - MEDIUM | 2015-11-06 | 2019-12-16 |
| CVE-2014-8140 | Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute... | 7.8 - HIGH | 2020-01-31 | 2023-02-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Unzip Project | Unzip | 6.0 | All | All | All |
| Application | Unzip Project | Unzip | 5.52 | All | All | All |
| Application | Unzip Project | Unzip | 5.51 | All | All | All |