zip4j_project CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

zip4j_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all zip4j_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling and vendor risk denial of service; exposure may include vendor impact file overwrite in vendor surface automated decompression contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-22899 Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive. [email protected] 5.9 0.26% 2023-01-10 2025-04-09
CVE-2022-24615 zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library. [email protected] 5.5 0.28% 2022-02-24 2024-11-21
CVE-2018-1002202 zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. [email protected] 6.5 3.72% 2018-07-25 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence