Search CVE reports


Toggle filters

1511 – 1520 of 1541 results


CVE-2016-10128

Medium priority
Vulnerable

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted...

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2014-9938

Medium priority
Fixed

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

1 affected package

git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
Show less packages

CVE-2016-8569

Low priority

Some fixes available 2 of 5

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected
Show less packages

CVE-2016-8568

Medium priority

Some fixes available 2 of 5

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected
Show less packages

CVE-2016-7569

Medium priority
Vulnerable

Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.

1 affected package

golang-github-appc-docker2aci

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-appc-docker2aci Not in release Not in release Vulnerable Vulnerable Not affected
Show less packages

CVE-2016-4340

Medium priority
Ignored

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release Not in release
Show less packages

CVE-2016-7794

Medium priority
Vulnerable

sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository name.

1 affected package

git-hub

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git-hub Not affected Not affected Not affected Not in release Not affected
Show less packages

CVE-2016-7793

Medium priority
Vulnerable

sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository URL.

1 affected package

git-hub

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git-hub Not affected Not affected Not affected Not in release Not affected
Show less packages

CVE-2016-9086

Medium priority
Ignored

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files...

1 affected package

gitlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2016-8579

Medium priority
Vulnerable

docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.

1 affected package

golang-github-appc-docker2aci

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-appc-docker2aci Not in release Not in release Vulnerable Vulnerable Vulnerable
Show less packages