Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cvs cvs vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-0753
Buffer overflow in CVS prior to 1.11.20 allows remote malicious users to execute arbitrary code.
Cvs Cvs 1.10
Cvs Cvs 1.11.11
Cvs Cvs 1.11.14
Cvs Cvs 1.11.6
Cvs Cvs 1.10.6
Cvs Cvs 1.10.7
Cvs Cvs 1.11.15
Cvs Cvs 1.11.16
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.10
Cvs Cvs 1.11.4
Cvs Cvs 1.11.5
Cvs Cvs 1.10.8
Cvs Cvs 1.11
Cvs Cvs 1.11.2
Cvs Cvs 1.11.3
1 Github repository
NA
CVE-2004-1342
CVS 1.12 and previous versions on Debian GNU/Linux, when using the repouid patch, allows remote malicious users to bypass authentication via the pserver access method.
Cvs Cvs 1.11.1
Cvs Cvs 1.11.10
Cvs Cvs 1.11.4
Cvs Cvs 1.11.6
Cvs Cvs 1.11.14
Cvs Cvs 1.11.15
Cvs Cvs 1.11.16
Cvs Cvs 1.11.2
Cvs Cvs 1.10
Cvs Cvs 1.10.6
Cvs Cvs 1.10.7
Cvs Cvs 1.10.8
Cvs Cvs 1.12
Cvs Cvs 1.11
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.11
Cvs Cvs 1.11.3
Cvs Cvs 1.11.5
NA
CVE-2004-1343
CVS 1.12 and previous versions on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote malicious users to cause a denial of service (server crash).
Cvs Cvs 1.10.7
Cvs Cvs 1.11
Cvs Cvs 1.11.16
Cvs Cvs 1.11.3
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.10
Cvs Cvs 1.11.11
Cvs Cvs 1.11.14
Cvs Cvs 1.10
Cvs Cvs 1.10.6
Cvs Cvs 1.11.5
Cvs Cvs 1.11.6
Cvs Cvs 1.12
Cvs Cvs 1.10.8
Cvs Cvs 1.11.1
Cvs Cvs 1.11.15
Cvs Cvs 1.11.2
Cvs Cvs 1.11.4
NA
CVE-2004-0414
CVS 1.12.x up to and including 1.12.8, and 1.11.x up to and including 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbit...
Cvs Cvs 1.11.14
Cvs Cvs 1.11.15
Cvs Cvs 1.12.1
Cvs Cvs 1.12.2
Sgi Propack 2.4
Sgi Propack 3.0
Cvs Cvs 1.11
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.3
Cvs Cvs 1.11.4
Cvs Cvs 1.12.8
Openpkg Openpkg
Cvs Cvs 1.10.7
Cvs Cvs 1.10.8
Cvs Cvs 1.11.16
Cvs Cvs 1.11.2
Cvs Cvs 1.12.5
Cvs Cvs 1.12.7
Cvs Cvs 1.11.10
Cvs Cvs 1.11.11
Cvs Cvs 1.11.5
NA
CVE-2004-0416
Double free vulnerability for the error_prog_name string in CVS 1.12.x up to and including 1.12.8, and 1.11.x up to and including 1.11.16, may allow remote malicious users to execute arbitrary code.
Cvs Cvs 1.10.7
Cvs Cvs 1.10.8
Cvs Cvs 1.11
Cvs Cvs 1.11.16
Cvs Cvs 1.11.2
Cvs Cvs 1.12.5
Cvs Cvs 1.12.7
Cvs Cvs 1.11.10
Cvs Cvs 1.11.11
Cvs Cvs 1.11.5
Cvs Cvs 1.11.6
Openpkg Openpkg 1.3
Openpkg Openpkg 2.0
Cvs Cvs 1.11.14
Cvs Cvs 1.11.15
Cvs Cvs 1.12.1
Cvs Cvs 1.12.2
Sgi Propack 2.4
Sgi Propack 3.0
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.3
1 EDB exploit
NA
CVE-2004-0417
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x up to and including 1.12.8, and 1.11.x up to and including 1.11.16, may allow remote malicious users to cause a server crash, which could cause temporary data to remain undeleted...
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.3
Cvs Cvs 1.11.4
Openpkg Openpkg
Openpkg Openpkg 1.3
Cvs Cvs 1.10.7
Cvs Cvs 1.11.14
Cvs Cvs 1.11.15
Cvs Cvs 1.12.1
Cvs Cvs 1.12.2
Sgi Propack 3.0
Cvs Cvs 1.10.8
Cvs Cvs 1.11
Cvs Cvs 1.11.16
Cvs Cvs 1.11.2
Cvs Cvs 1.12.5
Cvs Cvs 1.12.7
Cvs Cvs 1.12.8
Cvs Cvs 1.11.10
Cvs Cvs 1.11.11
Cvs Cvs 1.11.5
NA
CVE-2004-0418
serve_notify in CVS 1.12.x up to and including 1.12.8, and 1.11.x up to and including 1.11.16, does not properly handle empty data lines, which may allow remote malicious users to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify cri...
Cvs Cvs 1.11.10
Cvs Cvs 1.11.11
Cvs Cvs 1.11.6
Cvs Cvs 1.12.1
Openpkg Openpkg 2.0
Sgi Propack 2.4
Cvs Cvs 1.10.8
Cvs Cvs 1.11
Cvs Cvs 1.11.16
Cvs Cvs 1.11.2
Cvs Cvs 1.11.3
Cvs Cvs 1.12.7
Cvs Cvs 1.12.8
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.4
Cvs Cvs 1.11.5
Openpkg Openpkg
Openpkg Openpkg 1.3
Cvs Cvs 1.10.7
Cvs Cvs 1.11.14
Cvs Cvs 1.11.15
NA
CVE-2003-0977
CVS server prior to 1.11.10 may allow malicious users to cause the CVS server to create directories and files in the file system root directory via malformed module requests.
Cvs Cvs 1.10.7
Cvs Cvs 1.10.8
Cvs Cvs 1.11
Cvs Cvs 1.11.6
Cvs Cvs 1.11.4
Cvs Cvs 1.11.5
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1 P1
Cvs Cvs 1.11.2
Cvs Cvs 1.11.3
Slackware Slackware Linux 8.1
Slackware Slackware Linux 9.0
Slackware Slackware Linux 9.1
NA
CVE-2003-0015
Double-free vulnerability in CVS 1.11.4 and previous versions allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog comman...
Freebsd Freebsd 4.4
Freebsd Freebsd 4.5
Freebsd Freebsd 4.6
Freebsd Freebsd 4.7
Freebsd Freebsd 5.0
Cvs Cvs 1.11.1
Cvs Cvs 1.11.1p1
Cvs Cvs 1.10.8
Cvs Cvs 1.11
Cvs Cvs 1.11.2
Cvs Cvs 1.11.3
Cvs Cvs 1.10.7
Cvs Cvs 1.11.4
1 EDB exploit
NA
CVE-2012-0804
Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.
Cvs Cvs 1.11
Cvs Cvs 1.12
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-20065
open redirect
CVE-2024-1086
path traversal
CVE-2024-29825
XXE
CVE-2024-29822
CVE-2024-20696
CVE-2024-3564
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »