VendorsTarDiff Projecttardiffall versions
Vulnerabilities

TarDiff Project TarDiff

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-0857
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
Published 2016-05-06 · Modified
10.0EPSS 0.054
CVE-2015-0858
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
Published 2016-05-06 · Modified
3.3EPSS 0.004