Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17197
https://exchange.xforce.ibmcloud.com/vulnerabilities/17192
http://www.winzip.com/wz90sr1.htm
http://www.securityfocus.com/bid/11092
http://www.ciac.org/ciac/bulletins/o-211.shtml