CVE-2024-26308
- EPSS 0.43%
- Veröffentlicht 19.02.2024 09:15:38
- Zuletzt bearbeitet 27.03.2025 20:15:24
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.
CVE-2024-25710
- EPSS 0.01%
- Veröffentlicht 19.02.2024 09:15:37
- Zuletzt bearbeitet 13.02.2025 18:17:15
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.
CVE-2023-42503
- EPSS 0.01%
- Veröffentlicht 14.09.2023 08:15:08
- Zuletzt bearbeitet 13.02.2025 17:17:08
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0. Users are recommended to upgrade to version 1.24.0, which fixes...
CVE-2021-35515
- EPSS 0.11%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
CVE-2021-35516
- EPSS 0.28%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services tha...
CVE-2021-35517
- EPSS 0.28%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...
CVE-2021-36090
- EPSS 0.28%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:08
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services th...
CVE-2019-12402
- EPSS 0.38%
- Veröffentlicht 30.08.2019 09:15:17
- Zuletzt bearbeitet 21.11.2024 04:22:45
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names insi...
CVE-2018-11771
- EPSS 0.69%
- Veröffentlicht 16.08.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:59
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.Inpu...
CVE-2018-1324
- EPSS 0.48%
- Veröffentlicht 16.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:37
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service ...