← Vulnerability feed

Vulnerability record · CVE-2018-1000035 · published 9 February 2018

CVE-2018-1000035: Unzip project unzip out-of-bounds write vulnerability

UUnzip Project · Unzip

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

7.8 CVSS 3.0 High EPSS 30% · top 1.8% CWE-787 · Out-of-bounds write
7.8CVSS 3.0 base score, v2 6.8
30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1000035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2008-0888Canonical ubuntu linux memory buffer overflow vulnerabilityThe NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to caus…EPSS 6.3%9.1CVE-2020-36561Unzip project unzip path traversal vulnerabilityDue to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc…EPSS 1.3%7.8CVE-2014-8141Unzip project unzip out-of-bounds write vulnerabilityHeap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cra…EPSS 7.4%7.8CVE-2014-8139Unzip project unzip out-of-bounds write vulnerabilityHeap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafte…EPSS 7.4%7.8CVE-2014-8140Unzip project unzip out-of-bounds write vulnerabilityHeap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cr…EPSS 7.4%6.8CVE-2015-7696Canonical ubuntu linux memory buffer overflow vulnerabilityInfo-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbit…EPSS 7.2%5.5CVE-2022-0529Unzip project unzip out-of-bounds write vulnerabilityA flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri…EPSS 2.4%5.5CVE-2022-0530Unzip project unzip vulnerabilityA flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2018-1000035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.