Yawkat

Lz4 Java

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 06.10.2026 19:54:04
  • Zuletzt bearbeitet 07.10.2026 17:16:48

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied ...

  • EPSS 0.37%
  • Veröffentlicht 06.10.2026 19:52:37
  • Zuletzt bearbeitet 07.10.2026 13:58:29

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacke...

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 19:50:41
  • Zuletzt bearbeitet 07.10.2026 19:17:32

yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutput...

  • EPSS 0.37%
  • Veröffentlicht 06.10.2026 19:48:40
  • Zuletzt bearbeitet 07.10.2026 13:58:29

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode all...

  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:46:28
  • Zuletzt bearbeitet 07.10.2026 17:16:47

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of...

  • EPSS 0.46%
  • Veröffentlicht 18.08.2026 14:58:08
  • Zuletzt bearbeitet 18.09.2026 20:09:01

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance...