NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 82590 | CVE-2017-5946 | The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses ../ pathname substrings to write arbitrary files to the filesystem. | 2 | 7.5 | High | 2017-03-18 | 2017-03-02 | View | |
| 15066 | CVE-2010-3709 | The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive. | 2 | 4.3 | Medium | 2017-01-18 | 2016-08-22 | View | |
| 33385 | CVE-2014-5761 | The Zipcar (aka com.zc.android) application 3.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2 | 5.4 | Medium | 2017-01-19 | 2014-09-16 | View | |
| 43522 | CVE-2012-1650 | The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions. | 2 | 6 | Medium | 2017-01-19 | 2012-08-29 | View | |
| 19417 | CVE-2016-3620 | The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image. | 2 | 5 | Medium | 2017-01-19 | 2016-10-03 | View |
Page 15112 of 17672, showing 5 records out of 88360 total, starting on record 75556, ending on 75560