Skip to main content

Vendor/product archive

gnu / gzip CVEs

Beta · best-effort

13 CVEs tagged to gnu / gzip1 Critical, 2 High, 5 Medium, 5 Low, 0 Unrated.

CVE-2026-41992

Published Jun 29, 2026

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats wit…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-41991

Published Jun 29, 2026

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back t…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2010-0001

Published Jan 29, 2010

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2624

Published Jan 29, 2010

The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (appli…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0758

Published May 13, 2005

zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0988

Published May 2, 2005

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file w…

CVSS 3.7 · Low

CVE-2005-1228

Published May 2, 2005

Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename wi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0970

Published Feb 9, 2005

The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temp…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0603

Published Dec 6, 2004

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1349

Published Oct 4, 2004

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to v…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1228

Published Nov 18, 2001

Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1