Known Vulnerabilities for Tar by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Tar" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-5704 json | Not Provided | 2026-04-06 | 2026-04-22 | |
| CVE-2022-48303 json | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Ex... | 5.5 - MEDIUM | 2023-01-30 | 2023-05-30 |
| CVE-2021-20193 json | A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file ... | 5.5 - MEDIUM | 2021-03-26 | 2023-11-07 |
| CVE-2019-9923 json | pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have m... | 7.5 - HIGH | 2019-03-22 | 2023-11-07 |
| CVE-2018-20482 json | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause ... | 4.7 - MEDIUM | 2018-12-26 | 2021-11-30 |
| CVE-2016-6321 json | Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers... | 7.5 - HIGH | 2016-12-09 | 2023-02-13 |
| CVE-2010-0624 json | Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.2... | 6.8 - MEDIUM | 2010-03-15 | 2018-10-10 |
| CVE-2007-4476 json | Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crash... | 7.5 - HIGH | 2007-09-05 | 2021-05-17 |
| CVE-2007-4131 json | Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote atta... | 6.8 - MEDIUM | 2007-08-25 | 2018-10-15 |
| CVE-2006-6097 json | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar f... | 4 - MEDIUM | 2006-11-24 | 2018-10-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Tar | 1.32 | |||
| Application | Gnu | Tar | 1.31 | |||
| Application | Gnu | Tar | 1.30 | |||
| Application | Gnu | Tar | 1.29 | |||
| Application | Gnu | Tar | 1.28 | |||
| Application | Gnu | Tar | 1.27.1 | |||
| Application | Gnu | Tar | 1.27 | |||
| Application | Gnu | Tar | 1.26 | |||
| Application | Gnu | Tar | 1.25 | |||
| Application | Gnu | Tar | 1.24 | |||
| Application | Gnu | Tar | 1.23 | |||
| Application | Gnu | Tar | 1.22 | |||
| Application | Gnu | Tar | 1.21 | |||
| Application | Gnu | Tar | 1.20 | |||
| Application | Gnu | Tar | 1.19 | |||
| Application | Gnu | Tar | 1.18 | |||
| Application | Gnu | Tar | 1.17 | |||
| Application | Gnu | Tar | 1.16.1 | |||
| Application | Gnu | Tar | 1.16 | |||
| Application | Gnu | Tar | 1.15.91 |