Записи libgit2
11 опубликованных записей вендора libgit2.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 9,1 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-706 Use of Incorrectly-Resolved Name or Reference2
- CWE-20 Improper Input Validation2
- CWE-190 Integer Overflow or Wraparound1
- CWE-194 Unexpected Sign Extension1
- CWE-122 Heap-based Buffer Overflow1
- CWE-347 Improper Verification of Cryptographic Signature1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2014-9390Готовый эксплойт | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Критическая9,8 | — | 75,6 % | 11 февр. 2020 г. |
41В плане | CVE-2020-12278Эксплойта нет | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Критическая9,8 | — | 5,2 % | 27 апр. 2020 г. |
41В плане | CVE-2020-12279Эксплойта нет | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.libgit2 · libgit2 · CWE-706 | Критическая9,8 | — | 5,2 % | 27 апр. 2020 г. |
39Наблюдать | CVE-2024-24577Эксплойта нет | libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`libgit2 · libgit2 · CWE-122 | Критическая9,8 | — | 1,5 % | 6 февр. 2024 г. |
33Наблюдать | CVE-2018-10887Эксплойта нет | A flaw was found in libgit2 before version 0.27.3.libgit2 · libgit2 · CWE-194 | Высокая8,1 | — | 2,1 % | 10 июл. 2018 г. |
31Наблюдать | CVE-2018-15501Эксплойта нет | In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "libgit2 · libgit2 · CWE-125 | Высокая7,5 | — | 4,4 % | 17 авг. 2018 г. |
30Наблюдать | CVE-2024-24575Эксплойта нет | libgit2 is vulnerable to a denial of service attack in `git_revparse_single`libgit2 · libgit2 · CWE-400 | Высокая7,5 | — | 1,4 % | 6 февр. 2024 г. |
27Наблюдать | CVE-2018-10888Эксплойта нет | A flaw was found in libgit2 before version 0.27.3.libgit2 · libgit2 · CWE-20 | Средняя6,5 | — | 1,8 % | 10 июл. 2018 г. |
26Наблюдать | CVE-2018-8098Эксплойта нет | Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attlibgit2 · libgit2 · CWE-190 | Средняя6,5 | — | 1,4 % | 13 мар. 2018 г. |
26Наблюдать | CVE-2018-8099Эксплойта нет | Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an libgit2 · libgit2 · CWE-415 | Средняя6,5 | — | 1,4 % | 13 мар. 2018 г. |
23Наблюдать | CVE-2023-22742Эксплойта нет | libgit2 fails to verify SSH keys by defaultlibgit2 · libgit2 · CWE-347 | Средняя5,9 | — | 0,6 % | 20 янв. 2023 г. |
- CVE-2014-939062На этой неделе
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %mercurial · mercurial11 февр. 2020 г.
- CVE-2020-1227841В плане
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libgit2 · libgit227 апр. 2020 г.
- CVE-2020-1227941В плане
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libgit2 · libgit227 апр. 2020 г.
- CVE-2024-2457739Наблюдать
libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %libgit2 · libgit26 февр. 2024 г.
- CVE-2018-1088733Наблюдать
A flaw was found in libgit2 before version 0.27.3.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %libgit2 · libgit210 июл. 2018 г.
- CVE-2018-1550131Наблюдать
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %libgit2 · libgit217 авг. 2018 г.
- CVE-2024-2457530Наблюдать
libgit2 is vulnerable to a denial of service attack in `git_revparse_single`
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %libgit2 · libgit26 февр. 2024 г.
- CVE-2018-1088827Наблюдать
A flaw was found in libgit2 before version 0.27.3.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %libgit2 · libgit210 июл. 2018 г.
- CVE-2018-809826Наблюдать
Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an att
СредняяCVSS 6,5Эксплойта нетEPSS 1 %libgit2 · libgit213 мар. 2018 г.
- CVE-2018-809926Наблюдать
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an
СредняяCVSS 6,5Эксплойта нетEPSS 1 %libgit2 · libgit213 мар. 2018 г.
- CVE-2023-2274223Наблюдать
libgit2 fails to verify SSH keys by default
СредняяCVSS 5,9Эксплойта нетEPSS 1 %libgit2 · libgit220 янв. 2023 г.