296,733
Total vulnerabilities in the database
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Software | From | Fixed in |
---|---|---|
php / archive_tar | - | 1.4.12 |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
fedoraproject / fedora | 34 | 34.x |
fedoraproject / fedora | 35 | 35.x |
drupal / drupal | 7.0 | 7.75 |
drupal / drupal | 8.8.0 | 8.8.12 |
drupal / drupal | 8.0.0 | 8.9.10 |
drupal / drupal | 9.0.0 | 9.0.9 |
![]() |
- | 1.4.11 |