CVE-2022-37434Critical· 9.8▾ AbyssalPoC availablezlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 3.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
16%
16% → 18%
2 GitHub repos
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
zlib <= 1.2.12fedora = 35fedora = 36fedora = 37debian_linux = 10.0active_iq_unified_managerhcimanagement_services_for_element_softwareoncommand_workflow_automationontap_select_deploy_administration_utilitystoragegridhci_compute_nodeh300s_firmwareh500s_firmwareh700s_firmwareipados < 15.7.1iphone_os < 15.7.1iphone_os >= 16.0, < 16.1macos >= 11.0, < 11.7.1macos >= 12.0.0, < 12.6.1watchos < 9.1stormshield_network_security >= 3.7.31, < 3.7.34stormshield_network_security >= 3.11.0, < 3.11.22stormshield_network_security >= 4.3.0, < 4.3.16stormshield_network_security >= 4.6.0, < 4.6.3Upgrade past the affected range:
ipados 15.7.1iphone_os 16.1macos 12.6.1watchos 9.1stormshield_network_security 4.6.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-45853Critical· 9.8MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field
CVE-2026-22184High· 7.8zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz
CVE-2026-65334Medium· 4.3A memory corruption issue was addressed with improved state management
CVE-2026-65338Medium· 4.3The issue was addressed with improved memory handling
CVE-2026-65335Medium· 4.3This issue was addressed through improved state management
CVE-2026-65341Medium· 5.4The issue was addressed with improved memory handling