Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2005-4667

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.
0
Attacker Value
Unknown

CVE-2005-0602

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
0
Attacker Value
Unknown

CVE-2003-0282

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
0