Known vulnerabilities in cpio 2.8

Vendor: GNU
Software: cpio
Version: 2.8
Software CPE: cpe:2.3:a:gnu:cpio:*:*:*:*:*:*:*:*
Total vulnerabilities: 3
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting cpio version 2.8 cpio 2.8 is affected by 3 vulnerabilities: 2 high, 1 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85896 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-7207
CWE-22 High
No
No
2.14 30.01.2024 SB2024013015
SB2024013019
SB2024013020
and 12 more
#VU55853 - Integer overflow
CVE-2021-38185
CWE-190 High
Public exploit available
No
2.14 16.08.2021 SB2021081602
SB2021090901
SB2022051160
and 21 more
#VU22598 - Improper input validation
CVE-2019-14866
CWE-20 Low
No
No
- 07.11.2019 SB2019110723
SB2019110724
SB2019110742
and 15 more