VYPR

Vendor CVEs

Git

All CVEs

66 total · sorted by risk
  • CVE-2024-32004HigMay 14, 2024
    risk 0.00cvss 8.1epss 0.01

    Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions…

  • CVE-2023-29007HigApr 25, 2023
    risk 0.00cvss 7.0epss 0.06

    Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in…

  • CVE-2023-25815LowApr 25, 2023
    risk 0.00cvss 3.3epss 0.01

    In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's…

  • CVE-2023-23946MedFeb 14, 2023
    risk 0.00cvss 6.2epss 0.01

    Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is…

  • CVE-2023-22490MedFeb 14, 2023
    risk 0.00cvss 5.5epss 0.01

    Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though…

  • CVE-2021-40330HigAug 31, 2021
    risk 0.00cvss 7.5epss 0.03

    git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

  • CVE-2021-38711HigAug 16, 2021
    risk 0.00cvss 7.5epss 0.01

    In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.

  • CVE-2020-11008MedApr 21, 2020
    risk 0.00cvss 4.0epss 0.04

    Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_…

  • CVE-2018-19486CriNov 23, 2018
    risk 0.00cvss 9.8epss 0.04

    Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

  • CVE-2015-7082Dec 11, 2015
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Git before 2.5.4, as used in Apple Xcode before 7.2, have unknown impact and attack vectors. NOTE: this CVE is associated only with Xcode use cases.

  • CVE-2013-0308Mar 8, 2013
    risk 0.00cvss epss 0.02

    The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…

  • CVE-2010-2542Aug 11, 2010
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a working copy.

  • CVE-2008-5916Jan 21, 2009
    risk 0.00cvss epss 0.00

    gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repository owners to execute arbitrary commands by modifying the diff.external configuration variable and…

  • CVE-2008-5516Jan 20, 2009
    risk 0.00cvss epss 0.04

    The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_search.

  • CVE-2008-3546Aug 7, 2008
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.

  • CVE-2006-0477Jan 31, 2006
    risk 0.00cvss epss 0.03

    Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link.

Page 2 of 2