bzip kayıtları
bzip üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %72,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-416 Use After Free1
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-12900İstismar yok | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.bzip · bzip2 · CWE-787 | Kritik9,8 | — | %8,0 | 19 Haz 2019 |
31İzleyin | CVE-2016-3189İstismar yok | Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2bzip · bzip2 · CWE-416 | Orta6,5 | — | %15,6 | 30 Haz 2016 |
22İzleyin | CVE-2005-1260İstismar yok | bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (abzip · bzip2 · CWE-400 | Orta5,0 | — | %6,2 | 19 May 2005 |
21İzleyin | CVE-2010-0405İstismar yok | Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to caubzip · bzip2 · CWE-189 | Orta5,1 | — | %3,3 | 28 Eyl 2010 |
20İzleyin | CVE-2002-0759İstismar yok | bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag tbzip · bzip2 | Orta5,0 | — | %1,3 | 12 Ağu 2002 |
18İzleyin | CVE-2008-1372İstismar yok | bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a bzip · bzip2 · CWE-119 | Orta4,3 | — | %4,5 | 18 Mar 2008 |
18İzleyin | CVE-2009-1884İstismar yok | Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attacbzip · compress-raw-bzip2 · CWE-189 | Orta4,3 | — | %2,6 | 19 Ağu 2009 |
18İzleyin | CVE-2011-4089Kavram kanıtı | The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction,bzip · bzip2 · CWE-264 | Orta4,6 | — | %1,0 | 16 Nis 2014 |
14İzleyin | CVE-2005-0953İstismar yok | Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file whilebzip · bzip2 | Düşük3,7 | — | %0,4 | 2 May 2005 |
8İzleyin | CVE-2002-0761İstismar yok | bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links insteadbzip · bzip2 | Düşük2,1 | — | %0,4 | 12 Ağu 2002 |
4İzleyin | CVE-2002-0760İstismar yok | Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompressesbzip · bzip2 | Düşük1,2 | — | %0,3 | 12 Ağu 2002 |
- CVE-2019-1290041Planlayın
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
KritikCVSS 9,8İstismar yokEPSS %8bzip · bzip219 Haz 2019
- CVE-2016-318931İzleyin
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2
OrtaCVSS 6,5İstismar yokEPSS %16bzip · bzip230 Haz 2016
- CVE-2005-126022İzleyin
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a
OrtaCVSS 5,0İstismar yokEPSS %6bzip · bzip219 May 2005
- CVE-2010-040521İzleyin
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cau
OrtaCVSS 5,1İstismar yokEPSS %3bzip · bzip228 Eyl 2010
- CVE-2002-075920İzleyin
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag t
OrtaCVSS 5,0İstismar yokEPSS %1bzip · bzip212 Ağu 2002
- CVE-2008-137218İzleyin
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a
OrtaCVSS 4,3İstismar yokEPSS %5bzip · bzip218 Mar 2008
- CVE-2009-188418İzleyin
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attac
OrtaCVSS 4,3İstismar yokEPSS %3bzip · compress-raw-bzip219 Ağu 2009
- CVE-2011-408918İzleyin
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction,
OrtaCVSS 4,6Kavram kanıtıEPSS %1bzip · bzip216 Nis 2014
- CVE-2005-095314İzleyin
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while
DüşükCVSS 3,7İstismar yokEPSS %0bzip · bzip22 May 2005
- CVE-2002-07618İzleyin
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead
DüşükCVSS 2,1İstismar yokEPSS %0bzip · bzip212 Ağu 2002
- CVE-2002-07604İzleyin
Race condition in bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, decompresses
DüşükCVSS 1,2İstismar yokEPSS %0bzip · bzip212 Ağu 2002