CVE Tools

Winzip

8 CVEs tracked since 2002. Since Oct 2002, none of them reached CISA KEV.

Winzip CVEs per month

Oct 2002 to Jan 2007. Point at a month, or focus the strip and use the arrow keys.
Winzip CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2002-1010
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-0310
2004-04null or fewer
2004-0520
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-1120
2006-12null or fewer
2007-0120

Products

The products that kept showing up in Winzip's monthly top three, with their CVEs summed over those months.

  1. Winzip85 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Winzip.

  1. CVE-2025-33028In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection ...6.1
  2. CVE-2025-1240WinZip 7Z File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability8.8
  3. CVE-2024-8811WinZip Mark-of-the-Web Bypass Vulnerability7.8
  4. CVE-2008-3442WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade a...7.5
  5. CVE-2003-1376WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the st...4.6
  6. CVE-2007-0264Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument. NOTE: this i...6.6
  7. CVE-2006-6884Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a lo...9.3
  8. CVE-2006-3890Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code...9.3
  9. CVE-2006-5198The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "uns...4.0
  10. CVE-2004-1465Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.3.7
  11. CVE-2004-0235Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolut...6.4
  12. CVE-2004-0234Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbi...10.0
  13. CVE-2004-0333Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certai...10.0
  14. CVE-2002-0370Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, incl...7.5
  15. CVE-2001-0449Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.4.6

The record

Peak rank
#21 in May 2004
Busiest month shown
May 2004, 2 CVEs
Months with a KEV entry
0 since Oct 2002
Monthly snapshots
5 since 2002
Winzip's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store