Search CVE reports


Toggle filters

1531 – 1540 of 1547 results


CVE-2016-1899

Medium priority
Ignored

CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences...

1 affected package

cgit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cgit Not affected
Show less packages

CVE-2015-7545

Medium priority
Fixed

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote...

1 affected package

git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
Show less packages

CVE-2014-9390

Medium priority

Some fixes available 29 of 44

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...

5 affected packages

git, git-core, jgit, libgit2, mercurial

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git Fixed Fixed Fixed Fixed Fixed
git-core Not in release Not in release Not in release Not in release Not in release
jgit Not affected Not affected Not affected Not affected Not affected
libgit2 Not affected Not affected Not affected Not affected Not affected
mercurial Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2013-0308

Medium priority
Ignored

The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle...

2 affected packages

git, git-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
git-core
Show less packages

CVE-2012-4506

Medium priority
Not affected

Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other...

1 affected package

gitolite

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitolite
Show less packages

CVE-2011-1572

Medium priority
Ignored

Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.

1 affected package

gitolite

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitolite
Show less packages

CVE-2010-3906

Medium priority

Some fixes available 3 of 5

Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.

2 affected packages

git, git-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
git-core
Show less packages

CVE-2010-2542

Medium priority
Ignored

Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a working copy.

2 affected packages

git, git-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
git-core
Show less packages

CVE-2010-0394

High priority

Some fixes available 1 of 2

PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a...

1 affected package

trac-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trac-git
Show less packages

CVE-2009-2108

Low priority
Ignored

git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.

2 affected packages

git, git-core

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
git-core
Show less packages