threat
engine
.sh
Back
·
··:··
Home
/
Product
/
gnu cpio
Product
gnu cpio
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-7207
all versions
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caus
4.9
MEDIUM
CVE-2023-7216
all versions
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a
5.3
MEDIUM
CVE-2021-38185
<= 2.13
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr int
7.8
HIGH
CVE-2019-14866
< 2.13
In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to crea
7.3
HIGH
CVE-2016-2037
all versions
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds wri
6.5
MEDIUM
CVE-2015-1197
all versions
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a
CVE-2014-9112
all versions
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service v
CVE-2010-4226
all versions
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files v
7.2
HIGH
CVE-2010-0624
<= 2.10
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and
CVE-2005-4268
all versions
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of servi
CVE-2005-1229
<= 2.6
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot
CVE-2005-1111
<= 2.6
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a fil
4.7
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin