CVE-2018-25032High· 7.5▾ MidnightPoC availablezlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 10.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
52%
3 GitHub repos
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
nokogiri < 1.13.4python >= 3.7.0, < 3.7.14python >= 3.8.0, < 3.8.14python >= 3.9.0, < 3.9.13python >= 3.10.0, < 3.10.5zlib >= 1.2.2.2, < 1.2.12debian_linux = 9.0debian_linux = 10.0debian_linux = 11.0fedora = 34fedora = 35fedora = 36mac_os_x >= 10.15, < 10.15.7mac_os_x = 10.15.7macos >= 11.0, < 11.6.6macos >= 12.0.0, < 12.4mariadb >= 10.3.0, < 10.3.36mariadb >= 10.4.0, < 10.4.26mariadb >= 10.5.0, < 10.5.17mariadb >= 10.6.0, < 10.6.9mariadb >= 10.7.0, < 10.7.5mariadb >= 10.8.0, < 10.8.4mariadb >= 10.9.0, < 10.9.2active_iq_unified_managere-series_santricity_os_controller >= 11.0.0, <= 11.70.2management_services_for_element_softwareoncommand_workflow_automationontap_select_deploy_administration_utilityhci_compute_nodeh300s_firmwareh500s_firmwareh700s_firmwareh410s_firmwareh410c_firmwarescalance_sc622-2c_firmware < 3.0scalance_sc626-2c_firmware < 3.0scalance_sc632-2c_firmware < 3.0scalance_sc636-2c_firmware < 3.0scalance_sc642-2c_firmware < 3.0scalance_sc646-2c_firmware < 3.0zulu = 6.45zulu = 7.52zulu = 8.60zulu = 11.54zulu = 13.46zulu = 15.38zulu = 17.32gotoassist < 11.9.18Upgrade past the affected range:
nokogiri 1.13.4python 3.10.5zlib 1.2.12mac_os_x 10.15.7macos 12.4mariadb 10.9.2scalance_sc622-2c_firmware 3.0scalance_sc626-2c_firmware 3.0scalance_sc632-2c_firmware 3.0scalance_sc636-2c_firmware 3.0scalance_sc642-2c_firmware 3.0scalance_sc646-2c_firmware 3.0gotoassist 11.9.18Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37434Critical· 9.8zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field
CVE-2023-6931High· 7.8A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…
CVE-2025-15467High· 8.8Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …
CVE-2026-79770High· 7.5Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer
CVE-2022-50999High· 7.0Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-0995High· 7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem