bzip records
11 published records for vendor bzip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 72.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-416 Use After Free1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-12900No exploit | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.bzip · bzip2 · CWE-787 | Critical9.8 | — | 8.0% | Jun 19, 2019 |
31Monitor | CVE-2016-3189No exploit | Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2bzip · bzip2 · CWE-416 | Medium6.5 | — | 15.6% | Jun 30, 2016 |
22Monitor | CVE-2005-1260No exploit | bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (abzip · bzip2 · CWE-400 | Medium5.0 | — | 6.2% | May 19, 2005 |
21Monitor | CVE-2010-0405No exploit | Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to caubzip · bzip2 · CWE-189 | Medium5.1 | — | 3.3% | Sep 28, 2010 |
20Monitor | CVE-2002-0759No exploit | bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag tbzip · bzip2 | Medium5.0 | — | 1.3% | Aug 12, 2002 |
18Monitor | CVE-2008-1372No exploit | bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a bzip · bzip2 · CWE-119 | Medium4.3 | — | 4.5% | Mar 18, 2008 |
18Monitor | CVE-2009-1884No exploit | Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attacbzip · compress-raw-bzip2 · CWE-189 | Medium4.3 | — | 2.6% | Aug 19, 2009 |
18Monitor | CVE-2011-4089Proof of concept | The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction,bzip · bzip2 · CWE-264 | Medium4.6 | — | 1.0% | Apr 16, 2014 |
14Monitor | CVE-2005-0953No exploit | Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file whilebzip · bzip2 | Low3.7 | — | 0.4% | May 2, 2005 |
8Monitor | CVE-2002-0761No exploit | bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links insteadbzip · bzip2 | Low2.1 | — | 0.4% | Aug 12, 2002 |
4Monitor | CVE-2002-0760No exploit | Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompressesbzip · bzip2 | Low1.2 | — | 0.3% | Aug 12, 2002 |
- CVE-2019-1290041Plan
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
CriticalCVSS 9.8No exploitEPSS 8%bzip · bzip2Jun 19, 2019
- CVE-2016-318931Monitor
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2
MediumCVSS 6.5No exploitEPSS 16%bzip · bzip2Jun 30, 2016
- CVE-2005-126022Monitor
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a
MediumCVSS 5.0No exploitEPSS 6%bzip · bzip2May 19, 2005
- CVE-2010-040521Monitor
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cau
MediumCVSS 5.1No exploitEPSS 3%bzip · bzip2Sep 28, 2010
- CVE-2002-075920Monitor
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag t
MediumCVSS 5.0No exploitEPSS 1%bzip · bzip2Aug 12, 2002
- CVE-2008-137218Monitor
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a
MediumCVSS 4.3No exploitEPSS 5%bzip · bzip2Mar 18, 2008
- CVE-2009-188418Monitor
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attac
MediumCVSS 4.3No exploitEPSS 3%bzip · compress-raw-bzip2Aug 19, 2009
- CVE-2011-408918Monitor
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction,
MediumCVSS 4.6Proof of conceptEPSS 1%bzip · bzip2Apr 16, 2014
- CVE-2005-095314Monitor
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while
LowCVSS 3.7No exploitEPSS 0%bzip · bzip2May 2, 2005
- CVE-2002-07618Monitor
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead
LowCVSS 2.1No exploitEPSS 0%bzip · bzip2Aug 12, 2002
- CVE-2002-07604Monitor
Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses
LowCVSS 1.2No exploitEPSS 0%bzip · bzip2Aug 12, 2002