Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2015-1191
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
0
Attacker Value
Unknown
CVE-2013-0296
Disclosure Date: April 27, 2014 (last updated October 05, 2023)
Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring.
0
Attacker Value
Unknown
CVE-2005-1849
Disclosure Date: July 26, 2005 (last updated February 22, 2025)
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.
0
Attacker Value
Unknown
CVE-2005-2096
Disclosure Date: July 06, 2005 (last updated February 22, 2025)
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
0
Attacker Value
Unknown
CVE-2004-0797
Disclosure Date: October 20, 2004 (last updated February 22, 2025)
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).
0
Attacker Value
Unknown
CVE-2003-0107
Disclosure Date: March 07, 2003 (last updated February 22, 2025)
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2002-0059
Disclosure Date: March 15, 2002 (last updated February 22, 2025)
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute arbitrary code via a block of malformed compression data.
0