Количество 11
Количество 11
GHSA-mq29-j5xf-cjwr
pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency
CVE-2023-45853
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
CVE-2023-45853
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
CVE-2023-45853
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
CVE-2023-45853
CVE-2023-45853
MiniZip in zlib through 1.3 has an integer overflow and resultant heap ...
SUSE-SU-2023:4217-1
Security update for zlib
SUSE-SU-2023:4216-1
Security update for zlib
SUSE-SU-2023:4215-1
Security update for zlib
ROS-20231020-01
Уязвимость zlib
BDU:2023-07116
Уязвимость функции zipOpenNewFileInZip4_64() пакета MiniZip библиотеки zlib, позволяющая нарушителю оказать воздействие на целостность, доступность и конфиденциальность защищаемой информации
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
GHSA-mq29-j5xf-cjwr pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency  | CVSS3: 9.8  | 1% Низкий | около 2 лет назад | |
CVE-2023-45853 MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.  | CVSS3: 9.8  | 1% Низкий | около 2 лет назад | |
CVE-2023-45853 MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.  | CVSS3: 5.3  | 1% Низкий | около 2 лет назад | |
CVE-2023-45853 MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.  | CVSS3: 9.8  | 1% Низкий | около 2 лет назад | |
CVSS3: 9.8  | 1% Низкий | около 2 лет назад | ||
CVE-2023-45853 MiniZip in zlib through 1.3 has an integer overflow and resultant heap ...  | CVSS3: 9.8  | 1% Низкий | около 2 лет назад | |
SUSE-SU-2023:4217-1 Security update for zlib  | 1% Низкий | около 2 лет назад | ||
SUSE-SU-2023:4216-1 Security update for zlib  | 1% Низкий | около 2 лет назад | ||
SUSE-SU-2023:4215-1 Security update for zlib  | 1% Низкий | около 2 лет назад | ||
ROS-20231020-01 Уязвимость zlib  | CVSS3: 9.8  | 1% Низкий | около 2 лет назад | |
BDU:2023-07116 Уязвимость функции zipOpenNewFileInZip4_64() пакета MiniZip библиотеки zlib, позволяющая нарушителю оказать воздействие на целостность, доступность и конфиденциальность защищаемой информации  | CVSS3: 9.8  | 1% Низкий | около 2 лет назад | 
Уязвимостей на страницу