Known vulnerabilities in zip4j
Vendor:
Srikanth Reddy Lingala
Software:
zip4j
Software CPE:
cpe:2.3:a:srikanth_reddy_lingala:zip4j:*:*:*:*:*:*:*:*
Website:
https://www.lingala.net/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
2.11.6
2.11.5
2.11.4
2.11.3
2.11.2
2.11.1
2.11.0
2.10.0
2.9.1
2.9.0
2.8.0
2.7.0
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.2
2.5.1
2.5.0
2.4.0
2.3.2
2.3.1
2.3.0
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.1.4
2.1.3
2.1.2
2.1.0
2.0.3
2.0.2
2.0.1
2.0
1.3.2
1.3.1
1.3.0
1.2.9
1.2.8
1.2.7
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.9
1.1.8
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
1.3.3
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU74270 - Improper Verification of Cryptographic Signature CVE-2023-22899 |
CWE-347 | Medium | 2.11.3 | 31.03.2023 |
SB2023033140 SB2023040471 SB2023041871 and 6 more |
||
| #VU74269 - Improper input validation CVE-2022-24615 |
CWE-20 | Medium | 2.10.0 | 31.03.2023 |
SB2023033139 |
||
| #VU14134 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2018-1002202 |
CWE-22 | High | 1.3.3 | 30.07.2018 |
SB2018073111 |