📦

winzip

Vendor: winzip

Actively Exploited 0 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 3 Remote Access
Total CVEs 29 Total Indexed
Avg. EPSS 12.72% Exploit Prob.
Latest CVE CVE-2025-1240 Feb 11

Security Vulnerability Index

Page 2 / 3
10.0 CVSS

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.

EPSS: 10.26%
4.6 CVSS

WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.

EPSS: 0.24%
7.5 CVSS

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

EPSS: 43.30%
4.6 CVSS

Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.

EPSS: 0.42%