Перейти к содержимому
Noroxi

Записи git-scm

41 опубликованных записей вендора git-scm.

Профиль для исследователя

Попали в KEV
1 · 2,4 %
С эксплойтом
5 · 12,2 %
Pre-auth RCE
9
С записью об исправлении
95,1 %
Медиана: публикация → KEV
48 дн.

Все записи

41 записей
  • CVE-2018-17456
    68На этой неделе

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r

    КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %

    git-scm · git6 окт. 2018 г.

  • CVE-2025-48384
    63На этой неделе

    Git allows arbitrary code execution through broken config quoting

    ВысокаяCVSS 8,0KEVГотовый эксплойтEPSS 4 %

    git-scm · git8 июл. 2025 г.

  • CVE-2014-9390
    62На этой неделе

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before

    КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %

    mercurial · mercurial11 февр. 2020 г.

  • CVE-2017-1000117
    58В плане

    A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %

    git-scm · git4 окт. 2017 г.

  • CVE-2021-21300
    57В плане

    malicious repositories can execute remote code while cloning

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 89 %

    git-scm · git9 мар. 2021 г.

  • CVE-2022-23521
    56В плане

    gitattributes parsing integer overflow in git

    КритическаяCVSS 9,8Эксплойта нетEPSS 56 %

    git-scm · git17 янв. 2023 г.

  • CVE-2022-41903
    52В плане

    Integer overflow in `git archive`, `git log --format` leading to RCE in git

    КритическаяCVSS 9,8Proof of conceptEPSS 44 %

    git-scm · git17 янв. 2023 г.

  • CVE-2023-25652
    46В плане

    "git apply --reject" partially-controlled arbitrary file write

    ВысокаяCVSS 7,5Эксплойта нетEPSS 52 %

    git-scm · git25 апр. 2023 г.

  • CVE-2018-11235
    46В плане

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can

    ВысокаяCVSS 7,8Proof of conceptEPSS 49 %

    debian · debian linux30 мая 2018 г.

  • CVE-2017-14867
    46В плане

    Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to su

    ВысокаяCVSS 8,8Эксплойта нетEPSS 36 %

    git-scm · git28 сент. 2017 г.

  • CVE-2016-2324
    44В плане

    Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whi

    КритическаяCVSS 9,8Эксплойта нетEPSS 18 %

    suse · linux enterprise debuginfo8 апр. 2016 г.

  • CVE-2016-2315
    44В плане

    revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long f

    КритическаяCVSS 9,8Эксплойта нетEPSS 17 %

    suse · linux enterprise debuginfo8 апр. 2016 г.

  • CVE-2018-19486
    40В плане

    Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    linux · linux kernel23 нояб. 2018 г.

  • CVE-2019-1353
    40В плане

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    git-scm · git24 янв. 2020 г.

  • CVE-2019-1387
    36Наблюдать

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    git-scm · git18 дек. 2019 г.

  • CVE-2022-39260
    36Наблюдать

    Git vulnerable to Remote Code Execution via Heap overflow in `git shell`

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    git-scm · git19 окт. 2022 г.

  • CVE-2014-9938
    36Наблюдать

    contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    git-scm · git19 мар. 2017 г.

  • CVE-2020-5260
    33Наблюдать

    malicious URLs may cause Git to present stored credentials to the wrong server

    ВысокаяCVSS 7,5Proof of conceptEPSS 10 %

    git · git14 апр. 2020 г.

  • CVE-2022-41953
    33Наблюдать

    Git clone remote code execution vulnerability in git-for-windows

    ВысокаяCVSS 7,8Эксплойта нетEPSS 7 %

    git-scm · git17 янв. 2023 г.

  • CVE-2023-29007
    33Наблюдать

    Arbitrary configuration injection via `git submodule deinit`

    ВысокаяCVSS 7,8Proof of conceptEPSS 6 %

    git-scm · git25 апр. 2023 г.

  • CVE-2019-19604
    32Наблюдать

    Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x b

    ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %

    git-scm · git10 дек. 2019 г.

  • CVE-2018-11233
    31Наблюдать

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathn

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    canonical · ubuntu linux30 мая 2018 г.

  • CVE-2008-5516
    31Наблюдать

    The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    git · git20 янв. 2009 г.

  • CVE-2020-11008
    31Наблюдать

    Malicious URLs can still cause Git to send a stored credential to the wrong server

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    git-scm · git21 апр. 2020 г.

  • CVE-2021-40330
    31Наблюдать

    git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cr

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    git-scm · git31 авг. 2021 г.