cvs records
18 published records for vendor cvs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-415 Double Free1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2004-0396Proof of concept | Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers tocvs · cvs | High7.5 | — | 67.5% | Jun 14, 2004 |
44Plan | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Critical10.0 | — | 13.2% | Aug 6, 2004 |
43Plan | CVE-2012-0804No exploit | Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a decvs · cvs · CWE-119 | Critical10.0 | — | 8.5% | May 29, 2012 |
42Plan | CVE-2004-0418No exploit | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Critical10.0 | — | 5.7% | Aug 6, 2004 |
41Plan | CVE-2004-0414No exploit | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator frcvs · cvs | Critical10.0 | — | 4.0% | Aug 6, 2004 |
37Monitor | CVE-2003-0015Proof of concept | Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary codecvs · cvs · CWE-415 | High7.5 | — | 23.9% | Feb 7, 2003 |
31Monitor | CVE-2005-0753No exploit | Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.cvs · cvs | High7.5 | — | 4.7% | Apr 18, 2005 |
31Monitor | CVE-2003-0977No exploit | CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via cvs · cvs | High7.5 | — | 2.3% | Jan 5, 2004 |
31Monitor | CVE-2004-1342No exploit | CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acccvs · cvs | High7.5 | — | 2.3% | Apr 27, 2005 |
30Monitor | CVE-2004-1471Proof of concept | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commicvs · cvs | High7.1 | — | 7.7% | Dec 31, 2004 |
28Monitor | CVE-2000-0680Proof of concept | The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVScvs · cvs | High7.2 | — | 1.3% | Oct 20, 2000 |
21Monitor | CVE-2004-0417No exploit | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may cvs · cvs | Medium5.0 | — | 3.1% | Aug 6, 2004 |
21Monitor | CVE-2004-0405No exploit | CVS before 1.11 allows CVS clients to read arbitrary files via ..cvs · cvs | Medium5.0 | — | 2.4% | Jun 1, 2004 |
21Monitor | CVE-2004-1343No exploit | CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouicvs · cvs | Medium5.0 | — | 1.9% | Dec 31, 2004 |
21Monitor | CVE-2002-0092No exploit | CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) cvs · cvs | Medium5.0 | — | 1.8% | Mar 15, 2002 |
18Monitor | CVE-2005-2693No exploit | cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbicvs · cvs | Medium4.6 | — | 0.4% | Aug 26, 2005 |
11Monitor | CVE-2004-0180No exploit | The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolutecvs · cvs | Low2.6 | — | 1.8% | Jun 1, 2004 |
8Monitor | CVE-2000-0679Proof of concept | The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary cvs · cvs | Low2.1 | — | 0.7% | Oct 20, 2000 |
- CVE-2004-039650Plan
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 68%cvs · cvsJun 14, 2004
- CVE-2004-041644Plan
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
CriticalCVSS 10.0Proof of conceptEPSS 13%cvs · cvsAug 6, 2004
- CVE-2012-080443Plan
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a de
CriticalCVSS 10.0No exploitEPSS 8%cvs · cvsMay 29, 2012
- CVE-2004-041842Plan
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
CriticalCVSS 10.0No exploitEPSS 6%cvs · cvsAug 6, 2004
- CVE-2004-041441Plan
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr
CriticalCVSS 10.0No exploitEPSS 4%cvs · cvsAug 6, 2004
- CVE-2003-001537Monitor
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code
HighCVSS 7.5Proof of conceptEPSS 24%cvs · cvsFeb 7, 2003
- CVE-2005-075331Monitor
Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
HighCVSS 7.5No exploitEPSS 5%cvs · cvsApr 18, 2005
- CVE-2003-097731Monitor
CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via
HighCVSS 7.5No exploitEPSS 2%cvs · cvsJan 5, 2004
- CVE-2004-134231Monitor
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver acc
HighCVSS 7.5No exploitEPSS 2%cvs · cvsApr 27, 2005
- CVE-2004-147130Monitor
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi
HighCVSS 7.1Proof of conceptEPSS 8%cvs · cvsDec 31, 2004
- CVE-2000-068028Monitor
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS
HighCVSS 7.2Proof of conceptEPSS 1%cvs · cvsOct 20, 2000
- CVE-2004-041721Monitor
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may
MediumCVSS 5.0No exploitEPSS 3%cvs · cvsAug 6, 2004
- CVE-2004-040521Monitor
CVS before 1.11 allows CVS clients to read arbitrary files via ..
MediumCVSS 5.0No exploitEPSS 2%cvs · cvsJun 1, 2004
- CVE-2004-134321Monitor
CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repoui
MediumCVSS 5.0No exploitEPSS 2%cvs · cvsDec 31, 2004
- CVE-2002-009221Monitor
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash)
MediumCVSS 5.0No exploitEPSS 2%cvs · cvsMar 15, 2002
- CVE-2005-269318Monitor
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbi
MediumCVSS 4.6No exploitEPSS 0%cvs · cvsAug 26, 2005
- CVE-2004-018011Monitor
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute
LowCVSS 2.6No exploitEPSS 2%cvs · cvsJun 1, 2004
- CVE-2000-06798Monitor
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary
LowCVSS 2.1Proof of conceptEPSS 1%cvs · cvsOct 20, 2000