Записи cgit project
4 опубликованных записей вендора cgit project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 25 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2018-14912Готовый эксплойт | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstratecgit project · cgit · CWE-22 | Высокая7,5 | — | 92,0 % | 3 авг. 2018 г. |
40В плане | CVE-2016-1901Эксплойта нет | Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value fedoraproject · fedora · CWE-119 | Критическая9,8 | — | 3,8 % | 20 янв. 2016 г. |
15Наблюдать | CVE-2016-1899Эксплойта нет | CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conductfedoraproject · fedora | Низкая3,7 | — | 1,9 % | 20 янв. 2016 г. |
15Наблюдать | CVE-2016-1900Эксплойта нет | CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permissfedoraproject · fedora | Низкая3,7 | — | 1,9 % | 20 янв. 2016 г. |
- CVE-2018-1491258В плане
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrate
ВысокаяCVSS 7,5Готовый эксплойтEPSS 92 %cgit project · cgit3 авг. 2018 г.
- CVE-2016-190140В плане
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %fedoraproject · fedora20 янв. 2016 г.
- CVE-2016-189915Наблюдать
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct
НизкаяCVSS 3,7Эксплойта нетEPSS 2 %fedoraproject · fedora20 янв. 2016 г.
- CVE-2016-190015Наблюдать
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permiss
НизкаяCVSS 3,7Эксплойта нетEPSS 2 %fedoraproject · fedora20 янв. 2016 г.