Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
libgit2 libgit2 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-22742
libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2&...
Libgit2 Libgit2
Libgit2 Libgit2 1.5.0
7.5
CVSSv2
CVE-2016-10128
Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 prior to 0.24.6 and 0.25.x prior to 0.25.1 allows remote malicious users to have unspecified impact via a crafted non-flush packet.
Libgit2 Project Libgit2 0.25.0
Libgit2 Project Libgit2
5
CVSSv2
CVE-2016-10129
The Git Smart Protocol support in libgit2 prior to 0.24.6 and 0.25.x prior to 0.25.1 allows remote malicious users to cause a denial of service (NULL pointer dereference) via an empty packet line.
Libgit2 Project Libgit2 0.25.0
Libgit2 Project Libgit2
4.3
CVSSv2
CVE-2016-10130
The http_connect function in transports/http.c in libgit2 prior to 0.24.6 and 0.25.x prior to 0.25.1 might allow man-in-the-middle malicious users to spoof servers by leveraging clobbering of the error variable.
Libgit2 Project Libgit2
Libgit2 Project Libgit2 0.25.0
NA
CVE-2024-24575
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentia...
Libgit2 Libgit2
NA
CVE-2024-24577
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary ...
Libgit2 Libgit2
7.5
CVSSv2
CVE-2020-12279
An issue exists in libgit2 prior to 0.28.4 and 0.9x prior to 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.
Libgit2 Libgit2
Debian Debian Linux 9.0
7.5
CVSSv2
CVE-2020-12278
An issue exists in libgit2 prior to 0.28.4 and 0.9x prior to 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.
Libgit2 Libgit2
Debian Debian Linux 9.0
4.3
CVSSv2
CVE-2018-8098
Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an malicious user to cause a denial of service (out-of-bounds read) via a crafted repository index file.
Libgit2 Libgit2
Debian Debian Linux 9.0
4.3
CVSSv2
CVE-2018-8099
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an malicious user to cause a denial of service via a crafted repository index file.
Libgit2 Libgit2
Debian Debian Linux 9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »