CVE detail
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
36 source links · newest first
- Siemens CADRACISA Alerts
cations, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2005-2096 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow,
governmentwww.cisa.govJul 21, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-942865.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-565386.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-470355.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-419740.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-398330.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-333517.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - https://www.oracle.com/security-alerts/cpujul2022.htmlwww.oracle.com
No excerpt available.
Vendor Advisorywww.oracle.comMar 25, 2022, 9:15 AM - https://www.openwall.com/lists/oss-security/2022/03/28/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 25, 2022, 9:15 AM - https://www.openwall.com/lists/oss-security/2022/03/28/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 25, 2022, 9:15 AM - https://www.openwall.com/lists/oss-security/2022/03/24/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 25, 2022, 9:15 AM - https://www.debian.org/security/2022/dsa-5111www.debian.org
No excerpt available.
Vendor Advisorywww.debian.orgMar 25, 2022, 9:15 AM - https://support.apple.com/kb/HT213257support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMar 25, 2022, 9:15 AM - https://support.apple.com/kb/HT213256support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMar 25, 2022, 9:15 AM - https://support.apple.com/kb/HT213255support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comMar 25, 2022, 9:15 AM - https://security.netapp.com/advisory/ntap-20220729-0004/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comMar 25, 2022, 9:15 AM - https://security.netapp.com/advisory/ntap-20220526-0009/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comMar 25, 2022, 9:15 AM - https://security.gentoo.org/glsa/202210-42security.gentoo.org
No excerpt available.
Vendor Advisorysecurity.gentoo.orgMar 25, 2022, 9:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgMar 25, 2022, 9:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgMar 25, 2022, 9:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgMar 25, 2022, 9:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgMar 25, 2022, 9:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgMar 25, 2022, 9:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgMar 25, 2022, 9:15 AM No excerpt available.
Vendor Advisorylists.debian.orgMar 25, 2022, 9:15 AMNo excerpt available.
Vendor Advisorylists.debian.orgMar 25, 2022, 9:15 AMNo excerpt available.
Vendor Advisorylists.debian.orgMar 25, 2022, 9:15 AMNo excerpt available.
Exploitgithub.comMar 25, 2022, 9:15 AMNo excerpt available.
Exploitgithub.comMar 25, 2022, 9:15 AMNo excerpt available.
Exploitgithub.comMar 25, 2022, 9:15 AM- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdfcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMar 25, 2022, 9:15 AM - http://www.openwall.com/lists/oss-security/2022/03/26/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 25, 2022, 9:15 AM - http://www.openwall.com/lists/oss-security/2022/03/25/2www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 25, 2022, 9:15 AM - http://seclists.org/fulldisclosure/2022/May/38seclists.org
No excerpt available.
Exploitseclists.orgMar 25, 2022, 9:15 AM - http://seclists.org/fulldisclosure/2022/May/35seclists.org
No excerpt available.
Exploitseclists.orgMar 25, 2022, 9:15 AM - http://seclists.org/fulldisclosure/2022/May/33seclists.org
No excerpt available.
Exploitseclists.orgMar 25, 2022, 9:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-37434CVSS 9.8 · Critical
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetH…
- CVE-2022-43680CVSS 7.5 · High
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
- CVE-2023-2911CVSS 7.5 · High
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-re…
- CVE-2022-1586CVSS 9.1 · Critical
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode prop…
- CVE-2022-29824CVSS 6.5 · Medium
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory w…
- CVE-2022-32208CVSS 5.9 · Medium
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed…