Vulnerabilities > Libgit2

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-24575 Resource Exhaustion vulnerability in Libgit2
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.
network
low complexity
libgit2 CWE-400
7.5
2024-02-06 CVE-2024-24577 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libgit2
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application.
network
low complexity
libgit2 CWE-119
critical
9.8
2023-01-20 CVE-2023-22742 Improper Verification of Cryptographic Signature vulnerability in Libgit2
libgit2 is a cross-platform, linkable library implementation of Git.
network
high complexity
libgit2 CWE-347
5.9
2020-04-27 CVE-2020-12279 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
network
low complexity
libgit2 debian CWE-706
critical
9.8
2020-04-27 CVE-2020-12278 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
network
low complexity
libgit2 debian CWE-706
critical
9.8
2020-02-12 CVE-2014-9390 Improper Input Validation vulnerability in multiple products
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
network
low complexity
git-scm mercurial apple eclipse libgit2 CWE-20
7.5
2018-08-18 CVE-2018-15501 Out-of-bounds Read vulnerability in multiple products
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.
network
low complexity
debian libgit2 CWE-125
5.0
2018-07-10 CVE-2018-10888 Out-of-bounds Read vulnerability in multiple products
A flaw was found in libgit2 before version 0.27.3.
network
low complexity
libgit2 debian CWE-125
6.5
2018-07-10 CVE-2018-10887 Incorrect Conversion between Numeric Types vulnerability in multiple products
A flaw was found in libgit2 before version 0.27.3.
network
low complexity
libgit2 debian CWE-681
8.1
2018-03-14 CVE-2018-8099 Double Free vulnerability in multiple products
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
4.3