Filtered by vendor Ziparchive Project Subscriptions
Filtered by product Ziparchive Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-36943 1 Ziparchive Project 1 Ziparchive 2026-01-28 8.1 High
SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are symlinks. SSZipArchive will overwrite files on the filesystem when opening a malicious ZIP containing a symlink as the first item.
CVE-2023-39136 1 Ziparchive Project 1 Ziparchive 2024-11-21 5.5 Medium
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.