libgit2 project records
5 published records for vendor libgit2 project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-125 Out-of-bounds Read1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-10128No exploit | Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and libgit2 project · libgit2 · CWE-119 | Critical9.8 | — | 4.0% | Mar 24, 2017 |
31Monitor | CVE-2016-10129No exploit | The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL libgit2 project · libgit2 · CWE-476 | High7.5 | — | 3.6% | Mar 24, 2017 |
24Monitor | CVE-2016-10130No exploit | The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to libgit2 project · libgit2 · CWE-284 | Medium5.9 | — | 1.7% | Mar 24, 2017 |
23Monitor | CVE-2016-8568No exploit | The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) fedoraproject · fedora · CWE-125 | Medium5.5 | — | 1.9% | Feb 3, 2017 |
23Monitor | CVE-2016-8569No exploit | The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereferenclibgit2 project · libgit2 · CWE-476 | Medium5.5 | — | 1.8% | Feb 3, 2017 |
- CVE-2016-1012840Plan
Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and
CriticalCVSS 9.8No exploitEPSS 4%libgit2 project · libgit2Mar 24, 2017
- CVE-2016-1012931Monitor
The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL
HighCVSS 7.5No exploitEPSS 4%libgit2 project · libgit2Mar 24, 2017
- CVE-2016-1013024Monitor
The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to
MediumCVSS 5.9No exploitEPSS 2%libgit2 project · libgit2Mar 24, 2017
- CVE-2016-856823Monitor
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read)
MediumCVSS 5.5No exploitEPSS 2%fedoraproject · fedoraFeb 3, 2017
- CVE-2016-856923Monitor
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereferenc
MediumCVSS 5.5No exploitEPSS 2%libgit2 project · libgit2Feb 3, 2017