Skip to content
Noroxi

git-scm records

41 published records for vendor git-scm.

All records

41 records
  • CVE-2018-17456
    68This week

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r

    CriticalCVSS 9.8WeaponizedEPSS 97%

    git-scm · gitOct 6, 2018

  • CVE-2025-48384
    63This week

    Git allows arbitrary code execution through broken config quoting

    HighCVSS 8.0KEVWeaponizedEPSS 4%

    git-scm · gitJul 8, 2025

  • CVE-2014-9390
    62This week

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before

    CriticalCVSS 9.8WeaponizedEPSS 76%

    mercurial · mercurialFeb 11, 2020

  • A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog

    HighCVSS 8.8WeaponizedEPSS 78%

    git-scm · gitOct 4, 2017

  • malicious repositories can execute remote code while cloning

    HighCVSS 7.5WeaponizedEPSS 89%

    git-scm · gitMar 9, 2021

  • gitattributes parsing integer overflow in git

    CriticalCVSS 9.8No exploitEPSS 56%

    git-scm · gitJan 17, 2023

  • Integer overflow in `git archive`, `git log --format` leading to RCE in git

    CriticalCVSS 9.8Proof of conceptEPSS 44%

    git-scm · gitJan 17, 2023

  • "git apply --reject" partially-controlled arbitrary file write

    HighCVSS 7.5No exploitEPSS 52%

    git-scm · gitApr 25, 2023

  • In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can

    HighCVSS 7.8Proof of conceptEPSS 49%

    debian · debian linuxMay 30, 2018

  • Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to su

    HighCVSS 8.8No exploitEPSS 36%

    git-scm · gitSep 28, 2017

  • Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whi

    CriticalCVSS 9.8No exploitEPSS 18%

    suse · linux enterprise debuginfoApr 8, 2016

  • revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long f

    CriticalCVSS 9.8No exploitEPSS 17%

    suse · linux enterprise debuginfoApr 8, 2016

  • Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas

    CriticalCVSS 9.8No exploitEPSS 4%

    linux · linux kernelNov 23, 2018

  • An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.

    CriticalCVSS 9.8No exploitEPSS 2%

    git-scm · gitJan 24, 2020

  • CVE-2019-1387
    36Monitor

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.

    HighCVSS 8.8No exploitEPSS 4%

    git-scm · gitDec 18, 2019

  • Git vulnerable to Remote Code Execution via Heap overflow in `git shell`

    HighCVSS 8.8No exploitEPSS 3%

    git-scm · gitOct 19, 2022

  • CVE-2014-9938
    36Monitor

    contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to

    HighCVSS 8.8No exploitEPSS 2%

    git-scm · gitMar 19, 2017

  • CVE-2020-5260
    33Monitor

    malicious URLs may cause Git to present stored credentials to the wrong server

    HighCVSS 7.5Proof of conceptEPSS 10%

    git · gitApr 14, 2020

  • Git clone remote code execution vulnerability in git-for-windows

    HighCVSS 7.8No exploitEPSS 7%

    git-scm · gitJan 17, 2023

  • Arbitrary configuration injection via `git submodule deinit`

    HighCVSS 7.8Proof of conceptEPSS 6%

    git-scm · gitApr 25, 2023

  • Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x b

    HighCVSS 7.8No exploitEPSS 4%

    git-scm · gitDec 10, 2019

  • In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathn

    HighCVSS 7.5No exploitEPSS 4%

    canonical · ubuntu linuxMay 30, 2018

  • CVE-2008-5516
    31Monitor

    The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related

    HighCVSS 7.5No exploitEPSS 4%

    git · gitJan 20, 2009

  • Malicious URLs can still cause Git to send a stored credential to the wrong server

    HighCVSS 7.5No exploitEPSS 4%

    git-scm · gitApr 21, 2020

  • git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cr

    HighCVSS 7.5No exploitEPSS 3%

    git-scm · gitAug 31, 2021