Tar
Vendor:
First CVE: Jul 12, 2001 · Active for 25 years
18
Total CVEs
More Total CVEs than 93% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2001
25 years ago
Most Recent CVE
Apr 6, 2026
109 days ago
CVE Severity & Scoring
Tar18 CVEs
17%
61%
22%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local6 (33.3%)
Network2 (11.1%)
Unknown10 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (33.3%)
High2 (11.1%)
Unknown10 (55.6%)
User Interaction
None4 (22.2%)
Unknown10 (55.6%)
Required4 (22.2%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None7 (38.9%)
Unknown10 (55.6%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4476HIGH Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." | Sep 5, 2007 | 7.5 | 38 | NO | YES |
CVE-2016-6321HIGH Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write t | Dec 9, 2016 | 7.5 | 32 | NO | NO |
CVE-2005-2541HIGH Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges. | Aug 10, 2005 | 10.0 | 31 | NO | NO |
CVE-2010-0624MEDIUM Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to | Mar 15, 2010 | 6.8 | 25 | NO | NO |
CVE-2006-6097MEDIUM GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symboli | Nov 24, 2006 | 4.0 | 24 | NO | YES |
CVE-2022-48303MEDIUM GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been d | Jan 30, 2023 | 5.5 | 22 | NO | NO |
CVE-2026-5704MEDIUM A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content | Apr 6, 2026 | 5.5 | 21 | NO | NO |
CVE-2019-9923HIGH pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers. | Mar 22, 2019 | 7.5 | 20 | NO | NO |
CVE-2018-20482MEDIUM GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_ | Dec 26, 2018 | 4.7 | 19 | NO | NO |
CVE-2007-4131MEDIUM Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (sl | Aug 25, 2007 | 6.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Tar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.29 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.28 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.27.1 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.27 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.26 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.25 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.24 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.23 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.22 | 1 | 7.5 | 15.2% | 0 | 0 |
| 1.21 | 2 | 7.2 | 10.0% | 0 | 0 |
| 1.20 | 2 | 7.2 | 10.0% | 0 | 0 |
| 1.19 | 2 | 7.2 | 10.0% | 0 | 0 |
| 1.18 | 2 | 7.2 | 10.0% | 0 | 0 |
| 1.17 | 2 | 7.2 | 10.0% | 0 | 0 |
| 1.16.1 | 2 | 7.2 | 10.0% | 0 | 0 |
| 1.16 | 4 | 6.3 | 8.3% | 0 | 1 |
| 1.15.91 | 3 | 7.0 | 7.5% | 0 | 0 |
| 1.15.90 | 4 | 6.5 | 6.9% | 0 | 0 |
| 1.15.1 | 6 | 6.7 | 7.1% | 0 | 1 |
| 1.15 | 4 | 6.5 | 6.9% | 0 | 0 |