Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2017-12836

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."
0
Attacker Value
Unknown

CVE-2005-2693

Disclosure Date: August 26, 2005 (last updated October 04, 2023)
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
0
Attacker Value
Unknown

CVE-2004-1471

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.
0
Attacker Value
Unknown

CVE-2004-0417

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
0
Attacker Value
Unknown

CVE-2004-0416

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0418

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
0
Attacker Value
Unknown

CVE-2004-0414

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
0