Vulnerabilities > Cygwin

DATE CVE VULNERABILITY TITLE RISK
2021-04-29 CVE-2021-29468 Improper Input Validation vulnerability in Cygwin GIT
Cygwin Git is a patch set for the git command line tool for the cygwin environment.
network
low complexity
cygwin CWE-20
8.8
2017-07-21 CVE-2017-7523 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cygwin
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
network
low complexity
cygwin CWE-119
5.0
2017-04-21 CVE-2016-3067 Permissions, Privileges, and Access Controls vulnerability in Cygwin
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.
network
low complexity
cygwin CWE-264
critical
9.8