CVE-2020-24175: YZ1

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.

Affected products

  • YZ1 YZ1: version 0.30 only; version 0.32 only

Published 2021-02-22. Last modified 2026-07-09.