Перейти к содержимому
Noroxi

Записи git

15 опубликованных записей вендора git.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
86,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

15 записей
  • CVE-2024-32002
    45В плане

    Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution

    КритическаяCVSS 9,0Proof of conceptEPSS 29 %

    git · git14 мая 2024 г.

  • CVE-2022-25648
    40В плане

    The package git before 1.11.0 are vulnerable to Command Injection via git argument injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    git · git19 апр. 2022 г.

  • CVE-2017-8386
    39Наблюдать

    git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x b

    ВысокаяCVSS 8,8Proof of conceptEPSS 12 %

    git · git-shell1 июн. 2017 г.

  • CVE-2008-5517
    34Наблюдать

    The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related

    ВысокаяCVSS 7,5Proof of conceptEPSS 12 %

    git · git13 янв. 2009 г.

  • CVE-2020-5260
    33Наблюдать

    malicious URLs may cause Git to present stored credentials to the wrong server

    ВысокаяCVSS 7,5Proof of conceptEPSS 10 %

    git · git14 апр. 2020 г.

  • CVE-2008-5516
    31Наблюдать

    The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    git · git20 янв. 2009 г.

  • CVE-2008-3546
    31Наблюдать

    Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    git · git7 авг. 2008 г.

  • CVE-2006-0477
    31Наблюдать

    Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long sy

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    git · git31 янв. 2006 г.

  • CVE-2024-52005
    30Наблюдать

    The sideband payload is passed unfiltered to the terminal in git

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    git · git15 янв. 2025 г.

  • CVE-2009-2108
    22Наблюдать

    git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a reque

    СредняяCVSS 5,0Proof of conceptEPSS 6 %

    git · git18 июн. 2009 г.

  • CVE-2024-21531
    21Наблюдать

    All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the pro

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    1 окт. 2024 г.

  • CVE-2010-3906
    19Наблюдать

    Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via th

    СредняяCVSS 4,3Proof of conceptEPSS 6 %

    git · git17 дек. 2010 г.

  • CVE-2008-5916
    18Наблюдать

    gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    git · git20 янв. 2009 г.

  • CVE-2024-52006
    8Наблюдать

    Newline confusion in credential helpers can lead to credential exfiltration in git

    НизкаяCVSS 2,1Эксплойта нетEPSS 1 %

    git · git14 янв. 2025 г.

  • CVE-2024-50349
    8Наблюдать

    Git does not sanitize URLs when asking for credentials interactively

    НизкаяCVSS 2,1Эксплойта нетEPSS 1 %

    git · git14 янв. 2025 г.