Home/Product/apache commons compress
Product

apache commons compress

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-26308
>= 1.21 and < 1.26.0
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Co
5.5MEDIUM
CVE-2024-25710
>= 1.3 and < 1.26.0
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons
8.1HIGH
CVE-2023-42503
>= 1.22 and < 1.24.0
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue af
5.5MEDIUM
CVE-2021-36090
>= 1.0 and < 1.21
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an ou
7.5HIGH
CVE-2021-35517
>= 1.1 and <= 1.20
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an ou
7.5HIGH
CVE-2021-35516
>= 1.6 and <= 1.20
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out
7.5HIGH
CVE-2021-35515
>= 1.6 and <= 1.20
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infi
7.5HIGH
CVE-2019-12402
>= 1.15 and <= 1.18
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced
7.5HIGH
CVE-2018-11771
>= 1.7.0 and <= 1.17.0
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can f
5.5MEDIUM
CVE-2018-1324
>= 1.11 and <= 1.15
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used b
5.5MEDIUM
CVE-2012-2098
< 1.4.1
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin