Записи git-scm
41 опубликованных записей вендора git-scm.
Профиль для исследователя
- Попали в KEV
- 1 · 2,4 %
- С эксплойтом
- 5 · 12,2 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 95,1 %
- Медиана: публикация → KEV
- 48 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-190 Integer Overflow or Wraparound2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
41 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2018-17456Готовый эксплойт | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows rgit-scm · git · CWE-88 | Критическая9,8 | — | 97,4 % | 6 окт. 2018 г. |
63На этой неделе | CVE-2025-48384Готовый эксплойт | Git allows arbitrary code execution through broken config quotinggit-scm · git · CWE-59 | Высокая8,0 | KEV | 4,2 % | 8 июл. 2025 г. |
62На этой неделе | CVE-2014-9390Готовый эксплойт | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Критическая9,8 | — | 75,6 % | 11 февр. 2020 г. |
58В плане | CVE-2017-1000117Готовый эксплойт | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any proggit-scm · git · CWE-601 | Высокая8,8 | — | 77,8 % | 4 окт. 2017 г. |
57В плане | CVE-2021-21300Готовый эксплойт | malicious repositories can execute remote code while cloninggit-scm · git · CWE-59 | Высокая7,5 | — | 88,5 % | 9 мар. 2021 г. |
56В плане | CVE-2022-23521Эксплойта нет | gitattributes parsing integer overflow in gitgit-scm · git · CWE-190 | Критическая9,8 | — | 56,3 % | 17 янв. 2023 г. |
52В плане | CVE-2022-41903Proof of concept | Integer overflow in `git archive`, `git log --format` leading to RCE in gitgit-scm · git · CWE-190 | Критическая9,8 | — | 44,3 % | 17 янв. 2023 г. |
46В плане | CVE-2023-25652Эксплойта нет | "git apply --reject" partially-controlled arbitrary file writegit-scm · git · CWE-22 | Высокая7,5 | — | 51,9 % | 25 апр. 2023 г. |
46В плане | CVE-2018-11235Proof of concept | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can debian · debian linux · CWE-22 | Высокая7,8 | — | 48,8 % | 30 мая 2018 г. |
46В плане | CVE-2017-14867Эксплойта нет | Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to sugit-scm · git · CWE-78 | Высокая8,8 | — | 36,0 % | 28 сент. 2017 г. |
44В плане | CVE-2016-2324Эксплойта нет | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whisuse · linux enterprise debuginfo · CWE-119 | Критическая9,8 | — | 18,1 % | 8 апр. 2016 г. |
44В плане | CVE-2016-2315Эксплойта нет | revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long fsuse · linux enterprise debuginfo · CWE-119 | Критическая9,8 | — | 17,3 % | 8 апр. 2016 г. |
40В плане | CVE-2018-19486Эксплойта нет | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain caslinux · linux kernel · CWE-426 | Критическая9,8 | — | 4,1 % | 23 нояб. 2018 г. |
40В плане | CVE-2019-1353Эксплойта нет | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.git-scm · git | Критическая9,8 | — | 2,2 % | 24 янв. 2020 г. |
36Наблюдать | CVE-2019-1387Эксплойта нет | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.git-scm · git | Высокая8,8 | — | 4,4 % | 18 дек. 2019 г. |
36Наблюдать | CVE-2022-39260Эксплойта нет | Git vulnerable to Remote Code Execution via Heap overflow in `git shell`git-scm · git · CWE-122 | Высокая8,8 | — | 3,3 % | 19 окт. 2022 г. |
36Наблюдать | CVE-2014-9938Эксплойта нет | contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to git-scm · git · CWE-116 | Высокая8,8 | — | 2,3 % | 19 мар. 2017 г. |
33Наблюдать | CVE-2020-5260Proof of concept | malicious URLs may cause Git to present stored credentials to the wrong servergit · git · CWE-20 | Высокая7,5 | — | 10,0 % | 14 апр. 2020 г. |
33Наблюдать | CVE-2022-41953Эксплойта нет | Git clone remote code execution vulnerability in git-for-windowsgit-scm · git · CWE-426 | Высокая7,8 | — | 6,8 % | 17 янв. 2023 г. |
33Наблюдать | CVE-2023-29007Proof of concept | Arbitrary configuration injection via `git submodule deinit`git-scm · git · CWE-74 | Высокая7,8 | — | 6,1 % | 25 апр. 2023 г. |
32Наблюдать | CVE-2019-19604Эксплойта нет | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x bgit-scm · git · CWE-78 | Высокая7,8 | — | 3,7 % | 10 дек. 2019 г. |
31Наблюдать | CVE-2018-11233Эксплойта нет | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathncanonical · ubuntu linux · CWE-125 | Высокая7,5 | — | 4,5 % | 30 мая 2018 г. |
31Наблюдать | CVE-2008-5516Эксплойта нет | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | Высокая7,5 | — | 4,4 % | 20 янв. 2009 г. |
31Наблюдать | CVE-2020-11008Эксплойта нет | Malicious URLs can still cause Git to send a stored credential to the wrong servergit-scm · git · CWE-20 | Высокая7,5 | — | 3,9 % | 21 апр. 2020 г. |
31Наблюдать | CVE-2021-40330Эксплойта нет | git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected crgit-scm · git | Высокая7,5 | — | 2,9 % | 31 авг. 2021 г. |
- CVE-2018-1745668На этой неделе
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %git-scm · git6 окт. 2018 г.
- CVE-2025-4838463На этой неделе
Git allows arbitrary code execution through broken config quoting
ВысокаяCVSS 8,0KEVГотовый эксплойтEPSS 4 %git-scm · git8 июл. 2025 г.
- CVE-2014-939062На этой неделе
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %mercurial · mercurial11 февр. 2020 г.
- CVE-2017-100011758В плане
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog
ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %git-scm · git4 окт. 2017 г.
- CVE-2021-2130057В плане
malicious repositories can execute remote code while cloning
ВысокаяCVSS 7,5Готовый эксплойтEPSS 89 %git-scm · git9 мар. 2021 г.
- CVE-2022-2352156В плане
gitattributes parsing integer overflow in git
КритическаяCVSS 9,8Эксплойта нетEPSS 56 %git-scm · git17 янв. 2023 г.
- CVE-2022-4190352В плане
Integer overflow in `git archive`, `git log --format` leading to RCE in git
КритическаяCVSS 9,8Proof of conceptEPSS 44 %git-scm · git17 янв. 2023 г.
- CVE-2023-2565246В плане
"git apply --reject" partially-controlled arbitrary file write
ВысокаяCVSS 7,5Эксплойта нетEPSS 52 %git-scm · git25 апр. 2023 г.
- CVE-2018-1123546В плане
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can
ВысокаяCVSS 7,8Proof of conceptEPSS 49 %debian · debian linux30 мая 2018 г.
- CVE-2017-1486746В плане
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to su
ВысокаяCVSS 8,8Эксплойта нетEPSS 36 %git-scm · git28 сент. 2017 г.
- CVE-2016-232444В плане
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whi
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %suse · linux enterprise debuginfo8 апр. 2016 г.
- CVE-2016-231544В плане
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long f
КритическаяCVSS 9,8Эксплойта нетEPSS 17 %suse · linux enterprise debuginfo8 апр. 2016 г.
- CVE-2018-1948640В плане
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %linux · linux kernel23 нояб. 2018 г.
- CVE-2019-135340В плане
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %git-scm · git24 янв. 2020 г.
- CVE-2019-138736Наблюдать
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %git-scm · git18 дек. 2019 г.
- CVE-2022-3926036Наблюдать
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %git-scm · git19 окт. 2022 г.
- CVE-2014-993836Наблюдать
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %git-scm · git19 мар. 2017 г.
- CVE-2020-526033Наблюдать
malicious URLs may cause Git to present stored credentials to the wrong server
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %git · git14 апр. 2020 г.
- CVE-2022-4195333Наблюдать
Git clone remote code execution vulnerability in git-for-windows
ВысокаяCVSS 7,8Эксплойта нетEPSS 7 %git-scm · git17 янв. 2023 г.
- CVE-2023-2900733Наблюдать
Arbitrary configuration injection via `git submodule deinit`
ВысокаяCVSS 7,8Proof of conceptEPSS 6 %git-scm · git25 апр. 2023 г.
- CVE-2019-1960432Наблюдать
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x b
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %git-scm · git10 дек. 2019 г.
- CVE-2018-1123331Наблюдать
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathn
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %canonical · ubuntu linux30 мая 2018 г.
- CVE-2008-551631Наблюдать
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %git · git20 янв. 2009 г.
- CVE-2020-1100831Наблюдать
Malicious URLs can still cause Git to send a stored credential to the wrong server
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %git-scm · git21 апр. 2020 г.
- CVE-2021-4033031Наблюдать
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cr
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %git-scm · git31 авг. 2021 г.