Записи git
15 опубликованных записей вендора git.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 86,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-116 Improper Encoding or Escaping of Output3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2024-32002Proof of concept | Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Executiongit · git · CWE-22 | Критическая9,0 | — | 29,2 % | 14 мая 2024 г. |
40В плане | CVE-2022-25648Эксплойта нет | The package git before 1.11.0 are vulnerable to Command Injection via git argument injection.git · git · CWE-88 | Критическая9,8 | — | 4,9 % | 19 апр. 2022 г. |
39Наблюдать | CVE-2017-8386Proof of concept | git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x bgit · git-shell | Высокая8,8 | — | 12,4 % | 1 июн. 2017 г. |
34Наблюдать | CVE-2008-5517Proof of concept | The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-94 | Высокая7,5 | — | 11,9 % | 13 янв. 2009 г. |
33Наблюдать | CVE-2020-5260Proof of concept | malicious URLs may cause Git to present stored credentials to the wrong servergit · git · CWE-20 | Высокая7,5 | — | 10,0 % | 14 апр. 2020 г. |
31Наблюдать | CVE-2008-5516Эксплойта нет | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | Высокая7,5 | — | 4,4 % | 20 янв. 2009 г. |
31Наблюдать | CVE-2008-3546Эксплойта нет | Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to executegit · git · CWE-119 | Высокая7,5 | — | 4,3 % | 7 авг. 2008 г. |
31Наблюдать | CVE-2006-0477Эксплойта нет | Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long sygit · git | Высокая7,5 | — | 3,3 % | 31 янв. 2006 г. |
30Наблюдать | CVE-2024-52005Proof of concept | The sideband payload is passed unfiltered to the terminal in gitgit · git · CWE-116 | Высокая7,5 | — | 0,5 % | 15 янв. 2025 г. |
22Наблюдать | CVE-2009-2108Proof of concept | git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a requegit · git · CWE-399 | Средняя5,0 | — | 5,8 % | 18 июн. 2009 г. |
21Наблюдать | CVE-2024-21531Эксплойта нет | All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the proCWE-78 | Средняя5,3 | — | 0,9 % | 1 окт. 2024 г. |
19Наблюдать | CVE-2010-3906Proof of concept | Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via thgit · git · CWE-79 | Средняя4,3 | — | 5,6 % | 17 дек. 2010 г. |
18Наблюдать | CVE-2008-5916Эксплойта нет | gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other git · git · CWE-264 | Средняя4,6 | — | 0,5 % | 20 янв. 2009 г. |
8Наблюдать | CVE-2024-52006Эксплойта нет | Newline confusion in credential helpers can lead to credential exfiltration in gitgit · git · CWE-116 | Низкая2,1 | — | 1,1 % | 14 янв. 2025 г. |
8Наблюдать | CVE-2024-50349Эксплойта нет | Git does not sanitize URLs when asking for credentials interactivelygit · git · CWE-116 | Низкая2,1 | — | 0,7 % | 14 янв. 2025 г. |
- CVE-2024-3200245В плане
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
КритическаяCVSS 9,0Proof of conceptEPSS 29 %git · git14 мая 2024 г.
- CVE-2022-2564840В плане
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %git · git19 апр. 2022 г.
- CVE-2017-838639Наблюдать
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x b
ВысокаяCVSS 8,8Proof of conceptEPSS 12 %git · git-shell1 июн. 2017 г.
- CVE-2008-551734Наблюдать
The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %git · git13 янв. 2009 г.
- CVE-2020-526033Наблюдать
malicious URLs may cause Git to present stored credentials to the wrong server
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %git · git14 апр. 2020 г.
- CVE-2008-551631Наблюдать
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %git · git20 янв. 2009 г.
- CVE-2008-354631Наблюдать
Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %git · git7 авг. 2008 г.
- CVE-2006-047731Наблюдать
Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long sy
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %git · git31 янв. 2006 г.
- CVE-2024-5200530Наблюдать
The sideband payload is passed unfiltered to the terminal in git
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %git · git15 янв. 2025 г.
- CVE-2009-210822Наблюдать
git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a reque
СредняяCVSS 5,0Proof of conceptEPSS 6 %git · git18 июн. 2009 г.
- CVE-2024-2153121Наблюдать
All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the pro
СредняяCVSS 5,3Эксплойта нетEPSS 1 %1 окт. 2024 г.
- CVE-2010-390619Наблюдать
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via th
СредняяCVSS 4,3Proof of conceptEPSS 6 %git · git17 дек. 2010 г.
- CVE-2008-591618Наблюдать
gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other
СредняяCVSS 4,6Эксплойта нетEPSS 0 %git · git20 янв. 2009 г.
- CVE-2024-520068Наблюдать
Newline confusion in credential helpers can lead to credential exfiltration in git
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %git · git14 янв. 2025 г.
- CVE-2024-503498Наблюдать
Git does not sanitize URLs when asking for credentials interactively
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %git · git14 янв. 2025 г.