Vendorstukaanixzall versions
Vulnerabilities

tukaani xz 4.999.9 beta

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-3094
Xz: malicious code in distributed source
Published 2024-03-29 · Modified
10.0EPSS 0.860
CVE-2022-1271
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing filenames with two or more newlines where selected content and the target file names are embedded in crafted multi-line file names. This flaw allows a remote, low privileged attacker to force zgrep to write arbitrary files on the system.
Published 2022-08-31 · Modified
8.8EPSS 0.051
CVE-2015-4035
scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
Published 2017-07-25 · Modified
7.8EPSS 0.010
CVE-2020-22916
An issue discovered in XZ 5.2.5 allows attackers to cause a denial of service via decompression of a crafted file. NOTE: the vendor disputes the claims of "endless output" and "denial of service" because decompression of the 17,486 bytes always results in 114,881,179 bytes, which is often a reasonable size increase.
Published 2023-08-22 · Modified
5.5EPSS 0.002
CVE-2026-34743
XZ Utils: Buffer overflow in lzma_index_append()
Published 2026-04-02 · Modified
5.3EPSS 0.006