Known Vulnerabilities for Commons Compress by Apache
Listed below are 9 of the newest known vulnerabilities associated with "Commons Compress" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-42503 json | Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This iss... | 5.5 - MEDIUM | 2023-09-14 | 2023-10-20 |
| CVE-2021-36090 json | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to ... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35517 json | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to ... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35516 json | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to a... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35515 json | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2019-12402 json | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when f... | 7.5 - HIGH | 2019-08-30 | 2023-11-07 |
| CVE-2018-11771 json | When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream ... | 5.5 - MEDIUM | 2018-08-16 | 2023-11-07 |
| CVE-2018-1324 json | A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser u... | 5.5 - MEDIUM | 2018-03-16 | 2023-11-07 |
| CVE-2012-2098 json | Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in A... | 5 - MEDIUM | 2012-06-29 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Commons Compress | 1.9 | |||
| Application | Apache | Commons Compress | 1.8.1 | |||
| Application | Apache | Commons Compress | 1.8 | |||
| Application | Apache | Commons Compress | 1.7 | |||
| Application | Apache | Commons Compress | 1.6 | |||
| Application | Apache | Commons Compress | 1.19 | |||
| Application | Apache | Commons Compress | 1.18 | |||
| Application | Apache | Commons Compress | 1.17 | |||
| Application | Apache | Commons Compress | 1.16.1 | |||
| Application | Apache | Commons Compress | 1.16 | |||
| Application | Apache | Commons Compress | 1.15 | |||
| Application | Apache | Commons Compress | 1.14 | |||
| Application | Apache | Commons Compress | 1.13 | |||
| Application | Apache | Commons Compress | 1.12 | |||
| Application | Apache | Commons Compress | 1.11 | |||
| Application | Apache | Commons Compress | 1.10 |