Записи bzip
11 опубликованных записей вендора bzip.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 72,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-416 Use After Free1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-12900Эксплойта нет | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.bzip · bzip2 · CWE-787 | Критическая9,8 | — | 8,0 % | 19 июн. 2019 г. |
31Наблюдать | CVE-2016-3189Эксплойта нет | Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2bzip · bzip2 · CWE-416 | Средняя6,5 | — | 15,6 % | 30 июн. 2016 г. |
22Наблюдать | CVE-2005-1260Эксплойта нет | bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (abzip · bzip2 · CWE-400 | Средняя5,0 | — | 6,2 % | 19 мая 2005 г. |
21Наблюдать | CVE-2010-0405Эксплойта нет | Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to caubzip · bzip2 · CWE-189 | Средняя5,1 | — | 3,3 % | 28 сент. 2010 г. |
20Наблюдать | CVE-2002-0759Эксплойта нет | bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag tbzip · bzip2 | Средняя5,0 | — | 1,3 % | 12 авг. 2002 г. |
18Наблюдать | CVE-2008-1372Эксплойта нет | bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a bzip · bzip2 · CWE-119 | Средняя4,3 | — | 4,5 % | 18 мар. 2008 г. |
18Наблюдать | CVE-2009-1884Эксплойта нет | Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attacbzip · compress-raw-bzip2 · CWE-189 | Средняя4,3 | — | 2,6 % | 19 авг. 2009 г. |
18Наблюдать | CVE-2011-4089Proof of concept | The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction,bzip · bzip2 · CWE-264 | Средняя4,6 | — | 1,0 % | 16 апр. 2014 г. |
14Наблюдать | CVE-2005-0953Эксплойта нет | Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file whilebzip · bzip2 | Низкая3,7 | — | 0,4 % | 2 мая 2005 г. |
8Наблюдать | CVE-2002-0761Эксплойта нет | bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links insteadbzip · bzip2 | Низкая2,1 | — | 0,4 % | 12 авг. 2002 г. |
4Наблюдать | CVE-2002-0760Эксплойта нет | Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompressesbzip · bzip2 | Низкая1,2 | — | 0,3 % | 12 авг. 2002 г. |
- CVE-2019-1290041В плане
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %bzip · bzip219 июн. 2019 г.
- CVE-2016-318931Наблюдать
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2
СредняяCVSS 6,5Эксплойта нетEPSS 16 %bzip · bzip230 июн. 2016 г.
- CVE-2005-126022Наблюдать
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a
СредняяCVSS 5,0Эксплойта нетEPSS 6 %bzip · bzip219 мая 2005 г.
- CVE-2010-040521Наблюдать
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cau
СредняяCVSS 5,1Эксплойта нетEPSS 3 %bzip · bzip228 сент. 2010 г.
- CVE-2002-075920Наблюдать
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag t
СредняяCVSS 5,0Эксплойта нетEPSS 1 %bzip · bzip212 авг. 2002 г.
- CVE-2008-137218Наблюдать
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a
СредняяCVSS 4,3Эксплойта нетEPSS 5 %bzip · bzip218 мар. 2008 г.
- CVE-2009-188418Наблюдать
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attac
СредняяCVSS 4,3Эксплойта нетEPSS 3 %bzip · compress-raw-bzip219 авг. 2009 г.
- CVE-2011-408918Наблюдать
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction,
СредняяCVSS 4,6Proof of conceptEPSS 1 %bzip · bzip216 апр. 2014 г.
- CVE-2005-095314Наблюдать
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %bzip · bzip22 мая 2005 г.
- CVE-2002-07618Наблюдать
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %bzip · bzip212 авг. 2002 г.
- CVE-2002-07604Наблюдать
Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses
НизкаяCVSS 1,2Эксплойта нетEPSS 0 %bzip · bzip212 авг. 2002 г.