VendorsESTsoftalzipall versions
Vulnerabilities

ESTsoft ALZip

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2011-1336
Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.
Published 2011-07-07 · Modified
9.3EPSS 0.055
CVE-2018-5196
Alzip Stack Overflow Vulnerability
Published 2018-12-21 · Modified
8.8EPSS 0.014
CVE-2017-11323
Stack-based buffer overflow in ESTsoft ALZip 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted MS-DOS device file, as demonstrated by use of "AUX" as the initial substring of a filename.
Published 2017-08-19 · Modified
7.8EPSS 0.030
CVE-2019-12807
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking during the parsing of crafted ISO archive file format. By persuading a victim to open a specially-crafted ISO archive file, an attacker could execution arbitrary code.
Published 2019-08-13 · Modified
7.8EPSS 0.016
CVE-2018-10027
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: %PROGRAMFILES%\ESTsoft\ALZip\Formats, %PROGRAMFILES%\ESTsoft\ALZip\Coders, %PROGRAMFILES(X86)%\ESTsoft\ALZip\Formats, or %PROGRAMFILES(X86)%\ESTsoft\ALZip\Coders.
Published 2018-05-17 · Modified
7.8EPSS 0.004
CVE-2005-3194
Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code via a long filename in a compressed (1) ALZ, (2) ARJ, (3) ZIP, (4) UUE, or (5) XXE archive.
Published 2005-10-14 · Modified
5.1EPSS 0.031