Show filters
59 Total Results
Displaying 51-59 of 59
Sort by:
Attacker Value
Unknown

CVE-2017-1000451

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.
0
Attacker Value
Unknown

CVE-2017-17831

Disclosure Date: December 21, 2017 (last updated November 26, 2024)
GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.
0
Attacker Value
Unknown

CVE-2017-12976

Disclosure Date: August 20, 2017 (last updated November 08, 2023)
git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117.
0
Attacker Value
Unknown

CVE-2016-9274

Disclosure Date: November 11, 2016 (last updated November 25, 2024)
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
Attacker Value
Unknown

CVE-2015-7545

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.
0
Attacker Value
Unknown

CVE-2016-1900

Disclosure Date: January 20, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.
0
Attacker Value
Unknown

CVE-2016-1901

Disclosure Date: January 20, 2016 (last updated November 25, 2024)
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2016-1899

Disclosure Date: January 20, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype parameter, as demonstrated by a request to blob/cgit.c.
0
Attacker Value
Unknown

CVE-2015-7082

Disclosure Date: December 11, 2015 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in Git before 2.5.4, as used in Apple Xcode before 7.2, have unknown impact and attack vectors. NOTE: this CVE is associated only with Xcode use cases.
0