VendorsApachecommons_compressany version
Vulnerabilities

Apache Software Foundation Commons Compress any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-25710
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
Published 2024-02-19 · Modified
8.1EPSS 0.004
CVE-2019-12402
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
Published 2019-08-29 · Modified
7.5EPSS 0.162
CVE-2021-36090
Apache Commons Compress 1.0 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.129
CVE-2021-35516
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.124
CVE-2021-35515
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.116
CVE-2021-35517
Apache Commons Compress 1.1 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.106
CVE-2018-11771
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.
Published 2018-08-16 · Modified
5.5EPSS 0.053
CVE-2018-1324
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Published 2018-03-16 · Modified
5.5EPSS 0.037
CVE-2024-26308
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
Published 2024-02-19 · Modified
5.5EPSS 0.009
CVE-2023-42503
Apache Commons Compress: Denial of service via CPU consumption for malformed TAR file
Published 2023-09-14 · Modified
5.5EPSS 0.006
CVE-2012-2098
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
Published 2012-06-29 · Modified
5.0EPSS 0.128