Search: "zlib"

68 CVEs found

CVE-2002-0059
9.8 CRITICAL

The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow l...

Published: 2002-03-15
Products: 1
Vendors:
zlib

Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or poss...

Published: 2003-03-07
Products: 1
Vendors:
zlib

The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).

Published: 2004-10-20
Products: 1
Vendors:
zlib

zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to ...

Published: 2005-07-06
Products: 3
Vendors:
zlib
CVE-2005-1849
5.0 MEDIUM

inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.

Published: 2005-07-26
Products: 1
Vendors:
zlib
CVE-2005-2458
5.0 MEDIUM

inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".

Published: 2005-08-23
Products: 63
Vendors:
linux
CVE-2005-2459
5.0 MEDIUM

The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a c...

Published: 2005-08-23
Products: 64
Vendors:
linux debian
CVE-2006-5823
4.0 MEDIUM

The zlib_inflate function in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via a malformed filesystem that uses zlib compression that triggers memory corruption, as demons...

Published: 2006-11-09
Products: 211
Vendors:
linux
CVE-2007-2231
4.3 MEDIUM

Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) vi...

Published: 2007-04-25
Products: 37
Vendors:
dovecot

Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory al...

Published: 2008-04-10
Products: 7
Vendors:
canonical debian python
CVE-2008-1678
5.0 MEDIUM

Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple...

Published: 2008-07-10
Products: 3
Vendors:
openssl

Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncomp...

Published: 2008-09-04
Products: 22
Vendors:
wireshark
CVE-2009-1391
6.8 MEDIUM

Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to...

Published: 2009-06-16
Products: 13
Vendors:
paul_marquess

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to exec...

Published: 2009-12-15
Products: 11
Vendors:
microsoft adobe suse apple opensuse
CVE-2009-4355
5.0 MEDIUM

Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consum...

Published: 2010-01-14
Products: 71
Vendors:
redhat openssl
CVE-2010-0734
6.8 MEDIUM

content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which mi...

Published: 2010-03-19
Products: 35
Vendors:
curl
CVE-2011-0015
5.0 MEDIUM

Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large ...

Published: 2011-01-19
Products: 207
Vendors:
tor
CVE-2011-2174
4.3 MEDIUM

Double free vulnerability in the tvb_uncompress function in epan/tvbuff.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application cras...

Published: 2011-06-06
Products: 25
Vendors:
wireshark
CVE-2015-7054
6.8 MEDIUM

zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not initialize memory for an unspecified data structure, which allows remot...

Published: 2015-12-11
Products: 4
Vendors:
apple
CVE-2015-8721
5.5 MEDIUM

Buffer overflow in the tvb_uncompress function in epan/tvbuff_zlib.c in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 allows remote attackers to cause a denial of service (application crash) v...

Published: 2016-01-04
Products: 9
Vendors:
wireshark