Search: "zlib"

68 CVEs found

CVE-2016-6881
5.5 MEDIUM

The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.

Published: 2016-12-23
Products: 1
Vendors:
ffmpeg
CVE-2017-7609
5.5 MEDIUM

elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

Published: 2017-04-09
Products: 1
Vendors:
elfutils_project

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Published: 2017-05-23
Products: 37
Vendors:
nodejs redhat oracle zlib apple +4 more
CVE-2016-9841
9.8 CRITICAL

inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Published: 2017-05-23
Products: 62
Vendors:
netapp nodejs redhat oracle zlib +4 more

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Published: 2017-05-23
Products: 36
Vendors:
nodejs redhat oracle zlib canonical +3 more
CVE-2016-9843
9.8 CRITICAL

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

Published: 2017-05-23
Products: 46
Vendors:
netapp mariadb nodejs redhat oracle +5 more

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making...

Published: 2017-10-30
Products: 23
Vendors:
nodejs

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoi...

Published: 2018-07-19
Products: 4
Vendors:
debian wireshark
CVE-2019-12874
9.8 CRITICAL

An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a doub...

Published: 2019-06-18
Products: 1
Vendors:
videolan

The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server...

Published: 2020-04-07
Products: 15
Vendors:
netapp netty oracle fedoraproject debian
CVE-2020-11081
5.3 MEDIUM

osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll ...

Published: 2020-07-10
Products: 1
Vendors:
linuxfoundation

GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL...

Published: 2021-04-30
Products: 1
Vendors:
gog

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Published: 2022-03-25
Products: 73
Vendors:
netapp mariadb python microsoft zlib +7 more

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a he...

Published: 2022-07-19
Products: 3
Vendors:
debian gstreamer

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending ...

Published: 2022-07-19
Products: 3
Vendors:
debian gstreamer
CVE-2022-37434
9.8 CRITICAL

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. S...

Published: 2022-08-05
Products: 31
Vendors:
netapp zlib apple stormshield fedoraproject +1 more

Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These two objects (HTTPReque...

Published: 2022-09-21
Products: 3
Vendors:
apple
CVE-2023-3255
6.5 MEDIUM

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `...

Published: 2023-09-13
Products: 4
Vendors:
redhat qemu fedoraproject
CVE-2023-45853
9.8 CRITICAL

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported p...

Published: 2023-10-14
Products: 2
Vendors:
zlib smihica

Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.

Published: 2023-11-22
Products: 1
Vendors:
zlib-ng