Skip to content
Noroxi

cvs records

18 published records for vendor cvs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
83.3%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    18 records
    • Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to

      HighCVSS 7.5Proof of conceptEPSS 68%

      cvs · cvsJun 14, 2004

    • Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker

      CriticalCVSS 10.0Proof of conceptEPSS 13%

      cvs · cvsAug 6, 2004

    • Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a de

      CriticalCVSS 10.0No exploitEPSS 8%

      cvs · cvsMay 29, 2012

    • serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att

      CriticalCVSS 10.0No exploitEPSS 6%

      cvs · cvsAug 6, 2004

    • CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr

      CriticalCVSS 10.0No exploitEPSS 4%

      cvs · cvsAug 6, 2004

    • CVE-2003-0015
      37Monitor

      Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code

      HighCVSS 7.5Proof of conceptEPSS 24%

      cvs · cvsFeb 7, 2003

    • CVE-2005-0753
      31Monitor

      Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.

      HighCVSS 7.5No exploitEPSS 5%

      cvs · cvsApr 18, 2005

    • CVE-2003-0977
      31Monitor

      CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via

      HighCVSS 7.5No exploitEPSS 2%

      cvs · cvsJan 5, 2004

    • CVE-2004-1342
      31Monitor

      CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acc

      HighCVSS 7.5No exploitEPSS 2%

      cvs · cvsApr 27, 2005

    • CVE-2004-1471
      30Monitor

      Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi

      HighCVSS 7.1Proof of conceptEPSS 8%

      cvs · cvsDec 31, 2004

    • CVE-2000-0680
      28Monitor

      The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS

      HighCVSS 7.2Proof of conceptEPSS 1%

      cvs · cvsOct 20, 2000

    • CVE-2004-0417
      21Monitor

      Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may

      MediumCVSS 5.0No exploitEPSS 3%

      cvs · cvsAug 6, 2004

    • CVE-2004-0405
      21Monitor

      CVS before 1.11 allows CVS clients to read arbitrary files via ..

      MediumCVSS 5.0No exploitEPSS 2%

      cvs · cvsJun 1, 2004

    • CVE-2004-1343
      21Monitor

      CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repoui

      MediumCVSS 5.0No exploitEPSS 2%

      cvs · cvsDec 31, 2004

    • CVE-2002-0092
      21Monitor

      CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash)

      MediumCVSS 5.0No exploitEPSS 2%

      cvs · cvsMar 15, 2002

    • CVE-2005-2693
      18Monitor

      cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbi

      MediumCVSS 4.6No exploitEPSS 0%

      cvs · cvsAug 26, 2005

    • CVE-2004-0180
      11Monitor

      The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute

      LowCVSS 2.6No exploitEPSS 2%

      cvs · cvsJun 1, 2004

    • The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary

      LowCVSS 2.1Proof of conceptEPSS 1%

      cvs · cvsOct 20, 2000