Tar

Vendor:

First CVE: Jul 12, 2001 · Active for 25 years

18
Total CVEs
More Total CVEs than 93% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2001
25 years ago
Most Recent CVE
Apr 6, 2026
109 days ago

CVE Severity & Scoring

Tar18 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local6 (33.3%)
Network2 (11.1%)
Unknown10 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (33.3%)
High2 (11.1%)
Unknown10 (55.6%)
User Interaction
None4 (22.2%)
Unknown10 (55.6%)
Required4 (22.2%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None7 (38.9%)
Unknown10 (55.6%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Sep 5, 20077.538NOYES
Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write t
Dec 9, 20167.532NONO
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
Aug 10, 200510.031NONO
Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to
Mar 15, 20106.825NONO
GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symboli
Nov 24, 20064.024NOYES
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been d
Jan 30, 20235.522NONO
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content
Apr 6, 20265.521NONO
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
Mar 22, 20197.520NONO
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_
Dec 26, 20184.719NONO
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (sl
Aug 25, 20076.819NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Tar

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.2917.515.2%00
1.2817.515.2%00
1.27.117.515.2%00
1.2717.515.2%00
1.2617.515.2%00
1.2517.515.2%00
1.2417.515.2%00
1.2317.515.2%00
1.2217.515.2%00
1.2127.210.0%00
1.2027.210.0%00
1.1927.210.0%00
1.1827.210.0%00
1.1727.210.0%00
1.16.127.210.0%00
1.1646.38.3%01
1.15.9137.07.5%00
1.15.9046.56.9%00
1.15.166.77.1%01
1.1546.56.9%00