
srikanth-lingala/zip4j
Releases40
Frequency2 months 1 day
Last Release
Stars2.22K
A Java library for zip files and streams
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.9 MEDIUM | — | ||
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive. | |||
| 5.5 MEDIUM | 4.3 MEDIUM | ||
zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library. | |||