Skip to main content

Vendor/product archive

zlib / zlib CVEs

Beta · best-effort

15 CVEs tagged to zlib / zlib5 Critical, 6 High, 2 Medium, 2 Low, 0 Unrated.

CVE-2026-27171

Published Feb 18, 2026

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

CVSS 2.9 · Low
evidence mentions
6
Buzz score
44.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-22184

Published Jan 7, 2026

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonst…

CVSS 4.6 · Medium
evidence mentions
10
Buzz score
44.0
Vendor/product tagsBeta · best-effort

CVE-2025-0725

Published Feb 5, 2025

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an atta…

CVSS 7.3 · High
evidence mentions
8
Buzz score
36.5

CVE-2023-45853

Published Oct 14, 2023

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip…

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
47.7
Vendor/product tagsBeta · best-effort

CVE-2016-9842

Published May 23, 2017

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

CVSS 8.8 · High
evidence mentions
32
Buzz score
50.0

CVE-2005-1849

Published Jul 26, 2005

inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2096

Published Jul 6, 2005

zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater th…

CVSS 7.5 · High
evidence mentions
58
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2004-0797

Published Oct 20, 2004

The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0107

Published Mar 7, 2003

Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a deni…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0059

Published Mar 15, 2002

The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free…

CVSS 9.8 · Critical
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1