CVE-2020-24175: YZ1
High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.
Affected products
- YZ1 YZ1: version 0.30 only; version 0.32 only
Published 2021-02-22. Last modified 2026-07-09.