Known vulnerabilities in Archive_Tar
Vendor:
PHP Group
Software:
Archive_Tar
Software CPE:
cpe:2.3:a:php_group:archive_tar:*:*:*:*:*:php:*:*
Website:
https://php.net
Total vulnerabilities:
5
Public exploits:
4
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU55101 - Improper Link Resolution Before File Access ('Link Following') CVE-2021-32610 |
CWE-59 | High | 1.4.14 | 20.07.2021 |
SB2021072062 SB2021072221 SB2021102617 and 12 more |
||
| #VU49907 - UNIX Symbolic Link (Symlink) Following CVE-2020-36193 |
CWE-61 | High | 1.4.12 | 18.01.2021 |
SB2021012112 SB2021012113 SB2021012410 and 20 more |
||
| #VU48668 - Improper input validation CVE-2020-28949 |
CWE-20 | High | 1.4.11 | 19.11.2020 |
SB2020112607 SB2020112608 SB2020112609 and 20 more |
||
| #VU48669 - Deserialization of Untrusted Data CVE-2020-28948 |
CWE-502 | High | 1.4.11 | 19.11.2020 |
SB2020112607 SB2020112608 SB2020112609 and 21 more |
||
| #VU17066 - Deserialization of Untrusted Data CVE-2018-1000888 |
CWE-502 | Medium | 1.4.4 | 17.01.2019 |
SB2018122808 SB2019013101 SB2020061525 and 1 more |