Skip to main content

Vendor/product archive

git-scm / git CVEs

Beta · best-effort

41 CVEs tagged to git-scm / git9 Critical, 20 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2018-17456

Published Oct 6, 2018

Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2018-11235

Published May 30, 2018

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file,…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2018-11233

Published May 30, 2018

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1000021

Published Feb 9, 2018

GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15298

Published Oct 14, 2017

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. Thi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000117

Published Oct 5, 2017

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-14867

Published Sep 29, 2017

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, wh…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9938

Published Mar 20, 2017

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2324

Published Apr 8, 2016

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflo…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2016-2315

Published Apr 8, 2016

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leadi…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2013-0308

Published Mar 8, 2013

The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3906

Published Dec 17, 2010

Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2542

Published Aug 11, 2010

Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a wo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-41 of 41 CVEsPage 2 of 2