Vulnerabilities > Libgit2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-06 | CVE-2024-24575 | Resource Exhaustion vulnerability in Libgit2 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. | 7.5 |
2024-02-06 | CVE-2024-24577 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libgit2 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. | 9.8 |
2023-01-20 | CVE-2023-22742 | Improper Verification of Cryptographic Signature vulnerability in Libgit2 libgit2 is a cross-platform, linkable library implementation of Git. | 5.9 |
2020-04-27 | CVE-2020-12279 | Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. | 9.8 |
2020-04-27 | CVE-2020-12278 | Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. | 9.8 |
2020-02-12 | CVE-2014-9390 | Improper Input Validation vulnerability in multiple products Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem. | 9.8 |
2018-08-18 | CVE-2018-15501 | Out-of-bounds Read vulnerability in multiple products In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS. | 7.5 |
2018-07-10 | CVE-2018-10888 | Out-of-bounds Read vulnerability in multiple products A flaw was found in libgit2 before version 0.27.3. | 6.5 |
2018-07-10 | CVE-2018-10887 | Incorrect Conversion between Numeric Types vulnerability in multiple products A flaw was found in libgit2 before version 0.27.3. | 8.1 |
2018-03-14 | CVE-2018-8099 | Double Free vulnerability in multiple products Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file. | 6.5 |