{"id":"CVE-1999-0202","title":"The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.","summary":"The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.","severity":"high","cvss":7.5,"cvssVector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","published":"1997-01-01","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-0202","references":[{"url":"https://www.cve.org/CVERecord?id=CVE-1999-0202","label":"cve@mitre.org"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-0202","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02013,"epssPercentile":0.79756,"ingestedAt":"2026-06-22T15:59:08.161Z","slug":"CVE-1999-0202","body":"## Overview\n\nThe GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}