GNU / Cpio
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-66486 | Improper Output Encoding in GNU cpio | MEDIUM | 4.6 | Aug 10, 2026 |
| CVE-2026-66485 | Uncontrolled Memory Allocation in GNU cpio | MEDIUM | 4.6 | Aug 10, 2026 |
| CVE-2026-66484 | Path Traversal in GNU cpio | MEDIUM | 4.6 | Aug 10, 2026 |
| CVE-2023-7216 | Cpio: extraction allows symlinks which enables remote command execution | MEDIUM | 5.3 | Feb 5, 2024 |
| CVE-2023-7207 | cpio: path traversal vulnerability | MEDIUM | 5.5 | Jan 5, 2024 |
| CVE-2021-38185 | cpio: integer overflow in ds_fgetstr() in dstring.c can lead to an out-of-bounds write via a crafted pattern file | HIGH | 7.8 | Aug 7, 2021 |
| CVE-2019-14866 | cpio: improper input validation when writing tar header fields leads to unexpected tar generation | HIGH | 7.3 | Jan 7, 2020 |
| CVE-2016-2037 | cpio: out of bounds write | MEDIUM | 6.5 | Feb 22, 2016 |
| CVE-2015-1197 | cpio: directory traversal through symlinks | LOW | 1.9 | Feb 19, 2015 |
| CVE-2014-9112 | cpio: heap-based buffer overflow flaw in list_file() | MEDIUM | 5.0 | Dec 2, 2014 |
| CVE-2010-4226 | cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM pa… | HIGH | 7.2 | Feb 6, 2014 |
| CVE-2010-0624 | cpio: Heap-based buffer overflow by expanding a specially-crafted archive | MEDIUM | 6.8 | Mar 12, 2010 |
| CVE-2005-4268 | cpio large filesize buffer overflow | LOW | 3.7 | Dec 15, 2005 |
| CVE-2005-1229 | cpio directory traversal issue | MEDIUM | 4.6 | Apr 22, 2005 |
| CVE-2005-1111 | security flaw | MEDIUM | 4.7 | Apr 16, 2005 |
Showing 1 to 15 of 15 CVEs