Commons Compress
Vendor:
First CVE: Jun 29, 2012 · Active for 14 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Commons Compress over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2012
14 years ago
Most Recent CVE
Feb 19, 2024
886 days ago
CVE Severity & Scoring
Commons Compress11 CVEs
55%
45%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (45.5%)
Network5 (45.5%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High0 (0.0%)
Unknown1 (9.1%)
User Interaction
None5 (45.5%)
Unknown1 (9.1%)
Required5 (45.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (90.9%)
Unknown1 (9.1%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12402HIGH The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a | Aug 30, 2019 | 7.5 | 33 | NO | NO |
CVE-2021-36090HIGH When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35516HIGH When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35515HIGH When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35517HIGH When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 29 | NO | NO |
CVE-2012-2098MEDIUM Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attac | Jun 29, 2012 | 5.0 | 25 | NO | NO |
CVE-2018-11771MEDIUM When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the | Aug 16, 2018 | 5.5 | 23 | NO | NO |
CVE-2018-1324MEDIUM A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in | Mar 16, 2018 | 5.5 | 22 | NO | NO |
CVE-2024-26308MEDIUM Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommen | Feb 19, 2024 | 5.5 | 20 | NO | NO |
CVE-2024-25710MEDIUM Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are reco | Feb 19, 2024 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Commons Compress
Top CWEs
Versions
No cataloged versions.