Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
git project git vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2018-25083
The pullit package prior to 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.
Pull It Project Pull It
NA
CVE-2014-9706
The build_index_from_tree function in index.py in Dulwich prior to 0.9.9 allows remote malicious users to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.
Debian Debian Linux 7.0
Dulwich Project Dulwich
7.5
CVSSv3
CVE-2022-39208
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory are exposed and can be read by unauthenticated users. This directory contains all projects, including their bare git repos and build artifacts. This file disclosu...
Onedev Project Onedev
7.5
CVSSv3
CVE-2020-22284
A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and version 2.1.2 allows malicious users to access sensitive information via a crafted 6LoWPAN packet.
Lwip Project Lwip 2.1.2
5.9
CVSSv3
CVE-2017-11353
yadm (yet another dotfile manager) 1.10.0 has a race condition (related to the behavior of git commands in setting permissions for new files and directories), which potentially allows access to SSH and PGP keys.
Yadm Project Yadm 1.10.0
NA
CVE-2015-0838
Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich prior to 0.9.9 allows remote malicious users to execute arbitrary code via a crafted pack file.
Debian Debian Linux 7.0
Dulwich Project Dulwich
7.5
CVSSv3
CVE-2018-7032
webcheckout in myrepos up to and including 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM malicious user to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or a...
Myrepos Project Myrepos
5.5
CVSSv3
CVE-2020-21047
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vul...
Elfutils Project Elfutils 0.177
9.8
CVSSv3
CVE-2019-10803
push-dir up to and including 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an maliciou...
Push-dir Project Push-dir
NA
CVE-2024-32465
Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repo...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »