VendorsInfo-ZIPunzipany version
Vulnerabilities

Info-ZIP UnZip any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2005-0602
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
Published 2005-03-01 · Modified
6.2EPSS 0.004
CVE-2001-1268
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.
Published 2002-05-03 · Modified
2.1EPSS 0.007
CVE-2001-1269
Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.
Published 2002-05-03 · Modified
2.1EPSS 0.005