Known Vulnerabilities for Commons Compress by Apache
Listed below are 8 of the newest known vulnerabilities associated with "Commons Compress" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-36090 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to ... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35517 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to ... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35516 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to a... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35515 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2019-12402 | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when f... | 7.5 - HIGH | 2019-08-30 | 2023-11-07 |
| CVE-2018-11771 | When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream ... | 5.5 - MEDIUM | 2018-08-16 | 2023-11-07 |
| CVE-2018-1324 | A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser u... | 5.5 - MEDIUM | 2018-03-16 | 2023-11-07 |
| CVE-2012-2098 | Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in A... | 5 - MEDIUM | 2012-06-29 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Commons Compress | 1.9 | All | All | All |
| Application | Apache | Commons Compress | 1.8.1 | All | All | All |
| Application | Apache | Commons Compress | 1.8 | All | All | All |
| Application | Apache | Commons Compress | 1.7 | All | All | All |
| Application | Apache | Commons Compress | 1.6 | All | All | All |
| Application | Apache | Commons Compress | 1.19 | All | All | All |
| Application | Apache | Commons Compress | 1.18 | All | All | All |
| Application | Apache | Commons Compress | 1.17 | All | All | All |
| Application | Apache | Commons Compress | 1.16.1 | All | All | All |
| Application | Apache | Commons Compress | 1.16 | All | All | All |
| Application | Apache | Commons Compress | 1.15 | All | All | All |
| Application | Apache | Commons Compress | 1.14 | All | All | All |
| Application | Apache | Commons Compress | 1.13 | All | All | All |
| Application | Apache | Commons Compress | 1.12 | All | All | All |
| Application | Apache | Commons Compress | 1.11 | All | All | All |
| Application | Apache | Commons Compress | 1.10 | All | All | All |