Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2005-4667
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.
0
Attacker Value
Unknown
CVE-2005-0602
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
0
Attacker Value
Unknown
CVE-2003-0282
Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.
0