git-scm kayıtları
git-scm üreticisine ait 41 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,4
- Silahlaştırılmış
- 5 · %12,2
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %95,1
- Yayından KEV’e ortanca
- 48 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-190 Integer Overflow or Wraparound2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
41 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2018-17456Silahlaştırılmış | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows rgit-scm · git · CWE-88 | Kritik9,8 | — | %97,4 | 6 Eki 2018 |
63Bu hafta | CVE-2025-48384Silahlaştırılmış | Git allows arbitrary code execution through broken config quotinggit-scm · git · CWE-59 | Yüksek8,0 | KEV | %4,2 | 8 Tem 2025 |
62Bu hafta | CVE-2014-9390Silahlaştırılmış | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Kritik9,8 | — | %75,6 | 11 Şub 2020 |
58Planlayın | CVE-2017-1000117Silahlaştırılmış | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any proggit-scm · git · CWE-601 | Yüksek8,8 | — | %77,8 | 4 Eki 2017 |
57Planlayın | CVE-2021-21300Silahlaştırılmış | malicious repositories can execute remote code while cloninggit-scm · git · CWE-59 | Yüksek7,5 | — | %88,5 | 9 Mar 2021 |
56Planlayın | CVE-2022-23521İstismar yok | gitattributes parsing integer overflow in gitgit-scm · git · CWE-190 | Kritik9,8 | — | %56,3 | 17 Oca 2023 |
52Planlayın | CVE-2022-41903Kavram kanıtı | Integer overflow in `git archive`, `git log --format` leading to RCE in gitgit-scm · git · CWE-190 | Kritik9,8 | — | %44,3 | 17 Oca 2023 |
46Planlayın | CVE-2023-25652İstismar yok | "git apply --reject" partially-controlled arbitrary file writegit-scm · git · CWE-22 | Yüksek7,5 | — | %51,9 | 25 Nis 2023 |
46Planlayın | CVE-2018-11235Kavram kanıtı | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can debian · debian linux · CWE-22 | Yüksek7,8 | — | %48,8 | 30 May 2018 |
46Planlayın | CVE-2017-14867İstismar yok | Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to sugit-scm · git · CWE-78 | Yüksek8,8 | — | %36,0 | 28 Eyl 2017 |
44Planlayın | CVE-2016-2324İstismar yok | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whisuse · linux enterprise debuginfo · CWE-119 | Kritik9,8 | — | %18,1 | 8 Nis 2016 |
44Planlayın | CVE-2016-2315İstismar yok | revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long fsuse · linux enterprise debuginfo · CWE-119 | Kritik9,8 | — | %17,3 | 8 Nis 2016 |
40Planlayın | CVE-2018-19486İstismar yok | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain caslinux · linux kernel · CWE-426 | Kritik9,8 | — | %4,1 | 23 Kas 2018 |
40Planlayın | CVE-2019-1353İstismar yok | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.git-scm · git | Kritik9,8 | — | %2,2 | 24 Oca 2020 |
36İzleyin | CVE-2019-1387İstismar yok | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.git-scm · git | Yüksek8,8 | — | %4,4 | 18 Ara 2019 |
36İzleyin | CVE-2022-39260İstismar yok | Git vulnerable to Remote Code Execution via Heap overflow in `git shell`git-scm · git · CWE-122 | Yüksek8,8 | — | %3,3 | 19 Eki 2022 |
36İzleyin | CVE-2014-9938İstismar yok | contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to git-scm · git · CWE-116 | Yüksek8,8 | — | %2,3 | 19 Mar 2017 |
33İzleyin | CVE-2020-5260Kavram kanıtı | malicious URLs may cause Git to present stored credentials to the wrong servergit · git · CWE-20 | Yüksek7,5 | — | %10,0 | 14 Nis 2020 |
33İzleyin | CVE-2022-41953İstismar yok | Git clone remote code execution vulnerability in git-for-windowsgit-scm · git · CWE-426 | Yüksek7,8 | — | %6,8 | 17 Oca 2023 |
33İzleyin | CVE-2023-29007Kavram kanıtı | Arbitrary configuration injection via `git submodule deinit`git-scm · git · CWE-74 | Yüksek7,8 | — | %6,1 | 25 Nis 2023 |
32İzleyin | CVE-2019-19604İstismar yok | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x bgit-scm · git · CWE-78 | Yüksek7,8 | — | %3,7 | 10 Ara 2019 |
31İzleyin | CVE-2018-11233İstismar yok | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathncanonical · ubuntu linux · CWE-125 | Yüksek7,5 | — | %4,5 | 30 May 2018 |
31İzleyin | CVE-2008-5516İstismar yok | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | Yüksek7,5 | — | %4,4 | 20 Oca 2009 |
31İzleyin | CVE-2020-11008İstismar yok | Malicious URLs can still cause Git to send a stored credential to the wrong servergit-scm · git · CWE-20 | Yüksek7,5 | — | %3,9 | 21 Nis 2020 |
31İzleyin | CVE-2021-40330İstismar yok | git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected crgit-scm · git | Yüksek7,5 | — | %2,9 | 31 Ağu 2021 |
- CVE-2018-1745668Bu hafta
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows r
KritikCVSS 9,8SilahlaştırılmışEPSS %97git-scm · git6 Eki 2018
- CVE-2025-4838463Bu hafta
Git allows arbitrary code execution through broken config quoting
YüksekCVSS 8,0KEVSilahlaştırılmışEPSS %4git-scm · git8 Tem 2025
- CVE-2014-939062Bu hafta
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
KritikCVSS 9,8SilahlaştırılmışEPSS %76mercurial · mercurial11 Şub 2020
- CVE-2017-100011758Planlayın
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any prog
YüksekCVSS 8,8SilahlaştırılmışEPSS %78git-scm · git4 Eki 2017
- CVE-2021-2130057Planlayın
malicious repositories can execute remote code while cloning
YüksekCVSS 7,5SilahlaştırılmışEPSS %89git-scm · git9 Mar 2021
- CVE-2022-2352156Planlayın
gitattributes parsing integer overflow in git
KritikCVSS 9,8İstismar yokEPSS %56git-scm · git17 Oca 2023
- CVE-2022-4190352Planlayın
Integer overflow in `git archive`, `git log --format` leading to RCE in git
KritikCVSS 9,8Kavram kanıtıEPSS %44git-scm · git17 Oca 2023
- CVE-2023-2565246Planlayın
"git apply --reject" partially-controlled arbitrary file write
YüksekCVSS 7,5İstismar yokEPSS %52git-scm · git25 Nis 2023
- CVE-2018-1123546Planlayın
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can
YüksekCVSS 7,8Kavram kanıtıEPSS %49debian · debian linux30 May 2018
- CVE-2017-1486746Planlayın
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to su
YüksekCVSS 8,8İstismar yokEPSS %36git-scm · git28 Eyl 2017
- CVE-2016-232444Planlayın
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, whi
KritikCVSS 9,8İstismar yokEPSS %18suse · linux enterprise debuginfo8 Nis 2016
- CVE-2016-231544Planlayın
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long f
KritikCVSS 9,8İstismar yokEPSS %17suse · linux enterprise debuginfo8 Nis 2016
- CVE-2018-1948640Planlayın
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas
KritikCVSS 9,8İstismar yokEPSS %4linux · linux kernel23 Kas 2018
- CVE-2019-135340Planlayın
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
KritikCVSS 9,8İstismar yokEPSS %2git-scm · git24 Oca 2020
- CVE-2019-138736İzleyin
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
YüksekCVSS 8,8İstismar yokEPSS %4git-scm · git18 Ara 2019
- CVE-2022-3926036İzleyin
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
YüksekCVSS 8,8İstismar yokEPSS %3git-scm · git19 Eki 2022
- CVE-2014-993836İzleyin
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to
YüksekCVSS 8,8İstismar yokEPSS %2git-scm · git19 Mar 2017
- CVE-2020-526033İzleyin
malicious URLs may cause Git to present stored credentials to the wrong server
YüksekCVSS 7,5Kavram kanıtıEPSS %10git · git14 Nis 2020
- CVE-2022-4195333İzleyin
Git clone remote code execution vulnerability in git-for-windows
YüksekCVSS 7,8İstismar yokEPSS %7git-scm · git17 Oca 2023
- CVE-2023-2900733İzleyin
Arbitrary configuration injection via `git submodule deinit`
YüksekCVSS 7,8Kavram kanıtıEPSS %6git-scm · git25 Nis 2023
- CVE-2019-1960432İzleyin
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x b
YüksekCVSS 7,8İstismar yokEPSS %4git-scm · git10 Ara 2019
- CVE-2018-1123331İzleyin
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathn
YüksekCVSS 7,5İstismar yokEPSS %4canonical · ubuntu linux30 May 2018
- CVE-2008-551631İzleyin
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
YüksekCVSS 7,5İstismar yokEPSS %4git · git20 Oca 2009
- CVE-2020-1100831İzleyin
Malicious URLs can still cause Git to send a stored credential to the wrong server
YüksekCVSS 7,5İstismar yokEPSS %4git-scm · git21 Nis 2020
- CVE-2021-4033031İzleyin
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cr
YüksekCVSS 7,5İstismar yokEPSS %3git-scm · git31 Ağu 2021