İçeriğe atla
Noroxi

git kayıtları

git üreticisine ait 15 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%86,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

15 kayıt
  • CVE-2024-32002
    45Planlayın

    Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution

    KritikCVSS 9,0Kavram kanıtıEPSS %29

    git · git14 May 2024

  • CVE-2022-25648
    40Planlayın

    The package git before 1.11.0 are vulnerable to Command Injection via git argument injection.

    KritikCVSS 9,8İstismar yokEPSS %5

    git · git19 Nis 2022

  • CVE-2017-8386
    39İzleyin

    git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x b

    YüksekCVSS 8,8Kavram kanıtıEPSS %12

    git · git-shell1 Haz 2017

  • CVE-2008-5517
    34İzleyin

    The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related

    YüksekCVSS 7,5Kavram kanıtıEPSS %12

    git · git13 Oca 2009

  • CVE-2020-5260
    33İzleyin

    malicious URLs may cause Git to present stored credentials to the wrong server

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    git · git14 Nis 2020

  • CVE-2008-5516
    31İzleyin

    The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related

    YüksekCVSS 7,5İstismar yokEPSS %4

    git · git20 Oca 2009

  • CVE-2008-3546
    31İzleyin

    Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute

    YüksekCVSS 7,5İstismar yokEPSS %4

    git · git7 Ağu 2008

  • CVE-2006-0477
    31İzleyin

    Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long sy

    YüksekCVSS 7,5İstismar yokEPSS %3

    git · git31 Oca 2006

  • CVE-2024-52005
    30İzleyin

    The sideband payload is passed unfiltered to the terminal in git

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    git · git15 Oca 2025

  • CVE-2009-2108
    22İzleyin

    git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a reque

    OrtaCVSS 5,0Kavram kanıtıEPSS %6

    git · git18 Haz 2009

  • CVE-2024-21531
    21İzleyin

    All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the pro

    OrtaCVSS 5,3İstismar yokEPSS %1

    1 Eki 2024

  • CVE-2010-3906
    19İzleyin

    Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via th

    OrtaCVSS 4,3Kavram kanıtıEPSS %6

    git · git17 Ara 2010

  • CVE-2008-5916
    18İzleyin

    gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other

    OrtaCVSS 4,6İstismar yokEPSS %0

    git · git20 Oca 2009

  • Newline confusion in credential helpers can lead to credential exfiltration in git

    DüşükCVSS 2,1İstismar yokEPSS %1

    git · git14 Oca 2025

  • Git does not sanitize URLs when asking for credentials interactively

    DüşükCVSS 2,1İstismar yokEPSS %1

    git · git14 Oca 2025