VYPR

rpm package

opensuse/libgit2&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/libgit2&distro=openSUSE%20Tumbleweed

Vulnerabilities (29)

  • CVE-2026-53587HigAug 20, 2026
    affected < 1.9.6-1.1fixed 1.9.6-1.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_p

  • CVE-2026-53586MedAug 20, 2026
    affected < 1.9.6-1.1fixed 1.9.6-1.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite ini

  • CVE-2026-53585MedAug 20, 2026
    affected < 1.9.6-1.1fixed 1.9.6-1.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value

  • CVE-2026-53584MedAug 20, 2026
    affected < 1.9.6-1.1fixed 1.9.6-1.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from .gitmo

  • CVE-2026-53583MedAug 20, 2026
    affected < 1.9.6-1.1fixed 1.9.6-1.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp resul

  • CVE-2026-5917CriAug 11, 2026
    affected < 1.9.7-1.1fixed 1.9.7-1.1

    libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metac

  • CVE-2024-24577HigFeb 6, 2024
    affected < 1.7.2-1.1fixed 1.7.2-1.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary

  • CVE-2024-24575HigFeb 6, 2024
    affected < 1.7.2-2.1fixed 1.7.2-2.1

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentia

  • CVE-2024-24574MedFeb 5, 2024
    affected < 1.7.2-1.1fixed 1.7.2-1.1

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in ver

  • CVE-2023-22742MedJan 20, 2023
    affected < 1.5.1-1.1fixed 1.5.1-1.1

    libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2'

  • CVE-2022-29187HigJul 12, 2022
    affected < 1.7.1-3.1fixed 1.7.1-3.1

    Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, fo

  • CVE-2022-24765MedApr 12, 2022
    affected < 1.4.3-1.1fixed 1.4.3-1.1

    Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked

  • CVE-2019-1353CriJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none o

  • CVE-2019-1348LowJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitr

  • CVE-2019-1354HigJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.

  • CVE-2019-1352HigJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1351HigJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.

  • CVE-2019-1350HigJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1349HigJan 24, 2020
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

  • CVE-2019-1387HigDec 18, 2019
    affected < 1.1.1-1.2fixed 1.1.1-1.2

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attac

Page 1 of 2