libgit2 records
11 published records for vendor libgit2.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 4
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-706 Use of Incorrectly-Resolved Name or Reference2
- CWE-20 Improper Input Validation2
- CWE-190 Integer Overflow or Wraparound1
- CWE-194 Unexpected Sign Extension1
- CWE-122 Heap-based Buffer Overflow1
- CWE-347 Improper Verification of Cryptographic Signature1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2014-9390Weaponized | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Critical9.8 | — | 75.6% | Feb 11, 2020 |
41Plan | CVE-2020-12278No exploit | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Critical9.8 | — | 5.2% | Apr 27, 2020 |
41Plan | CVE-2020-12279No exploit | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Critical9.8 | — | 5.2% | Apr 27, 2020 |
39Monitor | CVE-2024-24577No exploit | libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`libgit2 · libgit2 · CWE-122 | Critical9.8 | — | 1.5% | Feb 6, 2024 |
33Monitor | CVE-2018-10887No exploit | A flaw was found in libgit2 before version 0.27.3.libgit2 · libgit2 · CWE-194 | High8.1 | — | 2.1% | Jul 10, 2018 |
31Monitor | CVE-2018-15501No exploit | In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "libgit2 · libgit2 · CWE-125 | High7.5 | — | 4.4% | Aug 17, 2018 |
30Monitor | CVE-2024-24575No exploit | libgit2 is vulnerable to a denial of service attack in `git_revparse_single`libgit2 · libgit2 · CWE-400 | High7.5 | — | 1.4% | Feb 6, 2024 |
27Monitor | CVE-2018-10888No exploit | A flaw was found in libgit2 before version 0.27.3.libgit2 · libgit2 · CWE-20 | Medium6.5 | — | 1.8% | Jul 10, 2018 |
26Monitor | CVE-2018-8098No exploit | Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attlibgit2 · libgit2 · CWE-190 | Medium6.5 | — | 1.4% | Mar 13, 2018 |
26Monitor | CVE-2018-8099No exploit | Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an libgit2 · libgit2 · CWE-415 | Medium6.5 | — | 1.4% | Mar 13, 2018 |
23Monitor | CVE-2023-22742No exploit | libgit2 fails to verify SSH keys by defaultlibgit2 · libgit2 · CWE-347 | Medium5.9 | — | 0.6% | Jan 20, 2023 |
- CVE-2014-939062This week
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
CriticalCVSS 9.8WeaponizedEPSS 76%mercurial · mercurialFeb 11, 2020
- CVE-2020-1227841Plan
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
CriticalCVSS 9.8No exploitEPSS 5%libgit2 · libgit2Apr 27, 2020
- CVE-2020-1227941Plan
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
CriticalCVSS 9.8No exploitEPSS 5%libgit2 · libgit2Apr 27, 2020
- CVE-2024-2457739Monitor
libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`
CriticalCVSS 9.8No exploitEPSS 2%libgit2 · libgit2Feb 6, 2024
- CVE-2018-1088733Monitor
A flaw was found in libgit2 before version 0.27.3.
HighCVSS 8.1No exploitEPSS 2%libgit2 · libgit2Jul 10, 2018
- CVE-2018-1550131Monitor
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "
HighCVSS 7.5No exploitEPSS 4%libgit2 · libgit2Aug 17, 2018
- CVE-2024-2457530Monitor
libgit2 is vulnerable to a denial of service attack in `git_revparse_single`
HighCVSS 7.5No exploitEPSS 1%libgit2 · libgit2Feb 6, 2024
- CVE-2018-1088827Monitor
A flaw was found in libgit2 before version 0.27.3.
MediumCVSS 6.5No exploitEPSS 2%libgit2 · libgit2Jul 10, 2018
- CVE-2018-809826Monitor
Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an att
MediumCVSS 6.5No exploitEPSS 1%libgit2 · libgit2Mar 13, 2018
- CVE-2018-809926Monitor
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an
MediumCVSS 6.5No exploitEPSS 1%libgit2 · libgit2Mar 13, 2018
- CVE-2023-2274223Monitor
libgit2 fails to verify SSH keys by default
MediumCVSS 5.9No exploitEPSS 1%libgit2 · libgit2Jan 20, 2023