git kayıtları
git üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %86,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-116 Improper Encoding or Escaping of Output3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2024-32002Kavram kanıtı | Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Executiongit · git · CWE-22 | Kritik9,0 | — | %29,2 | 14 May 2024 |
40Planlayın | CVE-2022-25648İstismar yok | The package git before 1.11.0 are vulnerable to Command Injection via git argument injection.git · git · CWE-88 | Kritik9,8 | — | %4,9 | 19 Nis 2022 |
39İzleyin | CVE-2017-8386Kavram kanıtı | git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x bgit · git-shell | Yüksek8,8 | — | %12,4 | 1 Haz 2017 |
34İzleyin | CVE-2008-5517Kavram kanıtı | The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-94 | Yüksek7,5 | — | %11,9 | 13 Oca 2009 |
33İzleyin | CVE-2020-5260Kavram kanıtı | malicious URLs may cause Git to present stored credentials to the wrong servergit · git · CWE-20 | Yüksek7,5 | — | %10,0 | 14 Nis 2020 |
31İzleyin | CVE-2008-5516İstismar yok | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | Yüksek7,5 | — | %4,4 | 20 Oca 2009 |
31İzleyin | CVE-2008-3546İstismar yok | Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to executegit · git · CWE-119 | Yüksek7,5 | — | %4,3 | 7 Ağu 2008 |
31İzleyin | CVE-2006-0477İstismar yok | Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long sygit · git | Yüksek7,5 | — | %3,3 | 31 Oca 2006 |
30İzleyin | CVE-2024-52005Kavram kanıtı | The sideband payload is passed unfiltered to the terminal in gitgit · git · CWE-116 | Yüksek7,5 | — | %0,5 | 15 Oca 2025 |
22İzleyin | CVE-2009-2108Kavram kanıtı | git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a requegit · git · CWE-399 | Orta5,0 | — | %5,8 | 18 Haz 2009 |
21İzleyin | CVE-2024-21531İstismar yok | All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the proCWE-78 | Orta5,3 | — | %0,9 | 1 Eki 2024 |
19İzleyin | CVE-2010-3906Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via thgit · git · CWE-79 | Orta4,3 | — | %5,6 | 17 Ara 2010 |
18İzleyin | CVE-2008-5916İstismar yok | gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other git · git · CWE-264 | Orta4,6 | — | %0,5 | 20 Oca 2009 |
8İzleyin | CVE-2024-52006İstismar yok | Newline confusion in credential helpers can lead to credential exfiltration in gitgit · git · CWE-116 | Düşük2,1 | — | %1,1 | 14 Oca 2025 |
8İzleyin | CVE-2024-50349İstismar yok | Git does not sanitize URLs when asking for credentials interactivelygit · git · CWE-116 | Düşük2,1 | — | %0,7 | 14 Oca 2025 |
- CVE-2024-3200245Planlayın
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
KritikCVSS 9,0Kavram kanıtıEPSS %29git · git14 May 2024
- CVE-2022-2564840Planlayın
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection.
KritikCVSS 9,8İstismar yokEPSS %5git · git19 Nis 2022
- CVE-2017-838639İzleyin
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x b
YüksekCVSS 8,8Kavram kanıtıEPSS %12git · git-shell1 Haz 2017
- CVE-2008-551734İzleyin
The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related
YüksekCVSS 7,5Kavram kanıtıEPSS %12git · git13 Oca 2009
- CVE-2020-526033İzleyin
malicious URLs may cause Git to present stored credentials to the wrong server
YüksekCVSS 7,5Kavram kanıtıEPSS %10git · git14 Nis 2020
- CVE-2008-551631İzleyin
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
YüksekCVSS 7,5İstismar yokEPSS %4git · git20 Oca 2009
- CVE-2008-354631İzleyin
Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute
YüksekCVSS 7,5İstismar yokEPSS %4git · git7 Ağu 2008
- CVE-2006-047731İzleyin
Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long sy
YüksekCVSS 7,5İstismar yokEPSS %3git · git31 Oca 2006
- CVE-2024-5200530İzleyin
The sideband payload is passed unfiltered to the terminal in git
YüksekCVSS 7,5Kavram kanıtıEPSS %1git · git15 Oca 2025
- CVE-2009-210822İzleyin
git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a reque
OrtaCVSS 5,0Kavram kanıtıEPSS %6git · git18 Haz 2009
- CVE-2024-2153121İzleyin
All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the pro
OrtaCVSS 5,3İstismar yokEPSS %11 Eki 2024
- CVE-2010-390619İzleyin
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via th
OrtaCVSS 4,3Kavram kanıtıEPSS %6git · git17 Ara 2010
- CVE-2008-591618İzleyin
gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other
OrtaCVSS 4,6İstismar yokEPSS %0git · git20 Oca 2009
- CVE-2024-520068İzleyin
Newline confusion in credential helpers can lead to credential exfiltration in git
DüşükCVSS 2,1İstismar yokEPSS %1git · git14 Oca 2025
- CVE-2024-503498İzleyin
Git does not sanitize URLs when asking for credentials interactively
DüşükCVSS 2,1İstismar yokEPSS %1git · git14 Oca 2025