CVE detail
CVE-2022-37434
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 18.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
33 source links · newest first
- Siemens CADRACISA Alerts
cations, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2005-2096 zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow,
governmentwww.cisa.govJul 21, 2026, 12:00 PM - https://cert-portal.siemens.com/productcert/html/ssa-561322.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comAug 5, 2022, 7:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-470355.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comAug 5, 2022, 7:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-398330.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comAug 5, 2022, 7:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-202008.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comAug 5, 2022, 7:15 AM - https://cert-portal.siemens.com/productcert/html/ssa-150063.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comAug 5, 2022, 7:15 AM - https://www.debian.org/security/2022/dsa-5218www.debian.org
No excerpt available.
Vendor Advisorywww.debian.orgAug 5, 2022, 7:15 AM - https://support.apple.com/kb/HT213494support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comAug 5, 2022, 7:15 AM - https://support.apple.com/kb/HT213493support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comAug 5, 2022, 7:15 AM - https://support.apple.com/kb/HT213491support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comAug 5, 2022, 7:15 AM - https://support.apple.com/kb/HT213490support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comAug 5, 2022, 7:15 AM - https://support.apple.com/kb/HT213489support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comAug 5, 2022, 7:15 AM - https://support.apple.com/kb/HT213488support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comAug 5, 2022, 7:15 AM - https://security.netapp.com/advisory/ntap-20230427-0007/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comAug 5, 2022, 7:15 AM - https://security.netapp.com/advisory/ntap-20220901-0005/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comAug 5, 2022, 7:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgAug 5, 2022, 7:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgAug 5, 2022, 7:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgAug 5, 2022, 7:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgAug 5, 2022, 7:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgAug 5, 2022, 7:15 AM No excerpt available.
Vendor Advisorylists.debian.orgAug 5, 2022, 7:15 AMNo excerpt available.
Exploitgithub.comAug 5, 2022, 7:15 AMNo excerpt available.
Exploitgithub.comAug 5, 2022, 7:15 AMNo excerpt available.
Exploitgithub.comAug 5, 2022, 7:15 AM- https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063github.com
No excerpt available.
Exploitgithub.comAug 5, 2022, 7:15 AM - https://github.com/ivd38/zlib_overflowgithub.com
No excerpt available.
Exploitgithub.comAug 5, 2022, 7:15 AM - https://github.com/curl/curl/issues/9271github.com
No excerpt available.
Exploitgithub.comAug 5, 2022, 7:15 AM - http://www.openwall.com/lists/oss-security/2022/08/09/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comAug 5, 2022, 7:15 AM - http://www.openwall.com/lists/oss-security/2022/08/05/2www.openwall.com
No excerpt available.
Exploitwww.openwall.comAug 5, 2022, 7:15 AM - http://seclists.org/fulldisclosure/2022/Oct/42seclists.org
No excerpt available.
Exploitseclists.orgAug 5, 2022, 7:15 AM - http://seclists.org/fulldisclosure/2022/Oct/41seclists.org
No excerpt available.
Exploitseclists.orgAug 5, 2022, 7:15 AM - http://seclists.org/fulldisclosure/2022/Oct/38seclists.org
No excerpt available.
Exploitseclists.orgAug 5, 2022, 7:15 AM - http://seclists.org/fulldisclosure/2022/Oct/37seclists.org
No excerpt available.
Exploitseclists.orgAug 5, 2022, 7:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
4 repository references · best confidence 0.90 · max 0 stars
- nodejs/nodeHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 3:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- madler/zlibHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 3:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- ivd38/zlib_overflowHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 3:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- curl/curlHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 3:11 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2018-25032CVSS 7.5 · High
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
- CVE-2022-23308CVSS 7.5 · High
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
- CVE-2022-40303CVSS 7.5 · High
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow.…
- CVE-2022-32208CVSS 5.9 · Medium
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed…
- CVE-2024-2398CVSS 8.6 · High
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts…
- CVE-2022-40304CVSS 7.8 · High
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case,…