Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bzip

First CVE: Aug 12, 2002Active for: 24 yearsTotal CVEs: 11
26.5
VTI Score
Low

Bzip is a data compression utility whose bzip2 implementation is embedded across numerous software projects and systems, making it a foundational component in the software supply chain despite its narrowly focused product scope. Vulnerabilities in this compression library recur through memory-safety weakness classes including out-of-bounds writes, use-after-free conditions, and uncontrolled resource consumption, exposures that are characteristic of native-code parsers and reflect the parsing complexity inherent to decompression algorithms. Defenders should inventory applications and systems bundling bzip2 rather than tracking the library in isolation, since remediation typically cascades through downstream vendors; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
4.7
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bzip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2002
23 years ago
Most Recent CVE
Jun 19, 2019
2,593 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12900CRITICAL
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
Jun 19, 20199.834NONO
CVE-2016-3189MEDIUM
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to befo
Jun 30, 20166.529NONO
CVE-2011-4089MEDIUM
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arb
Apr 16, 20144.628NOYES
CVE-2010-0405MEDIUM
Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application cras
Sep 28, 20105.121NONO
CVE-2005-1260MEDIUM
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
May 19, 20055.019NONO
CVE-2009-1884MEDIUM
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (appli
Aug 19, 20094.317NONO
CVE-2008-1372MEDIUM
bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the
Mar 18, 20084.315NONO
CVE-2002-0759MEDIUM
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and
Aug 12, 20025.015NONO
CVE-2005-0953LOW
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permiss
May 2, 20053.714NONO
CVE-2002-0761LOW
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an ar
Aug 12, 20022.111NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
64%
9%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network2 (18.2%)
Unknown9 (81.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (18.2%)
High0 (0.0%)
Unknown9 (81.8%)
User Interaction
None1 (9.1%)
Unknown9 (81.8%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (18.2%)
Unknown9 (81.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bzip.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bzip — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bzip's Products

View all 2 CNAs →

Top CWEs