CVE-2018-1000021
- EPSS 0.37%
- Veröffentlicht 09.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:26
GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious ...
CVE-2017-15298
- EPSS 0.45%
- Veröffentlicht 14.10.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected pro...
CVE-2017-1000117
- EPSS 75.87%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of ...
- EPSS 6.97%
- Veröffentlicht 29.09.2017 01:34:50
- Zuletzt bearbeitet 20.04.2025 01:37:25
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacha...
CVE-2014-9938
- EPSS 0.75%
- Veröffentlicht 20.03.2017 00:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
- EPSS 22.05%
- Veröffentlicht 08.04.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
- EPSS 17.65%
- Veröffentlicht 08.04.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CVE-2013-0308
- EPSS 1.29%
- Veröffentlicht 08.03.2013 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL serve...
CVE-2010-3906
- EPSS 13.92%
- Veröffentlicht 17.12.2010 19:00:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.
CVE-2010-2542
- EPSS 2.14%
- Veröffentlicht 11.08.2010 18:47:50
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a working copy.