Software
git
Aggregate across all detected versions
Total Hosts
37
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
60
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2015-7082 | 10.0 | HIGH | Multiple unspecified vulnerabilities in Git before 2.5.4, as used in Apple Xcode before 7.2, have unknown impact and attack vectors. NOTE: this CVE is associat... |
| CVE-2014-9390 | 9.8 | N/A | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows an... |
| CVE-2015-7545 | 9.8 | N/A | The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do... |
| CVE-2016-2315 | 9.8 | N/A | revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many... |
| CVE-2016-2324 | 9.8 | N/A | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-b... |
| CVE-2018-17456 | 9.8 | N/A | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution... |
| CVE-2018-19486 | 9.8 | N/A | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run... |
| CVE-2019-1353 | 9.8 | N/A | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the... |
| CVE-2022-23521 | 9.8 | N/A | Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These attributes can be defined by adding a `.... |
| CVE-2022-41903 | 9.8 | N/A | Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` specifiers. This functionality is also exp... |
| CVE-2020-5260 | 9.3 | N/A | Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external... |
| CVE-2024-32002 | 9.0 | N/A | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a... |
| CVE-2014-9938 | 8.8 | N/A | contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution... |
| CVE-2017-1000117 | 8.8 | N/A | A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on t... |
| CVE-2017-14867 | 8.8 | N/A | Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands su... |
| CVE-2019-1387 | 8.8 | N/A | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are cur... |
| CVE-2021-29468 | 8.8 | N/A | Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that contains symbolic links as well as files... |
| CVE-2022-36882 | 8.8 | N/A | A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attac... |
| CVE-2024-52005 | 8.8 | N/A | Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git... |
| CVE-2022-41953 | 8.6 | N/A | Git GUI is a convenient graphical tool that comes with Git for Windows. Its target audience is users who are uncomfortable with using Git on the command-line. G... |
| CVE-2022-39260 | 8.5 | N/A | Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull func... |
| CVE-2022-31012 | 8.2 | N/A | Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute... |
| CVE-2022-25648 | 8.1 | N/A | The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the... |
| CVE-2024-32004 | 8.1 | N/A | Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in su... |
| CVE-2021-21300 | 8.0 | N/A | Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as fi... |
| CVE-2025-48384 | 8.0 | N/A | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to inte... |
| CVE-2018-11235 | 7.8 | N/A | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafte... |
| CVE-2019-19604 | 7.8 | N/A | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because... |
| CVE-2022-29187 | 7.8 | N/A | Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privile... |
| CVE-2006-0477 | 7.5 | HIGH | Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link. |
| CVE-2008-3546 | 7.5 | HIGH | Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via... |
| CVE-2008-5516 | 7.5 | HIGH | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_search. |
| CVE-2008-5517 | 7.5 | HIGH | The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot... |
| CVE-2010-2542 | 7.5 | HIGH | Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in... |
| CVE-2017-1000092 | 7.5 | N/A | Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/... |
| CVE-2018-11233 | 7.5 | N/A | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can res... |
| CVE-2021-40330 | 7.5 | N/A | git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol request... |
| CVE-2021-46101 | 7.5 | N/A | In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly. |
| CVE-2022-24975 | 7.5 | N/A | The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security... |
| CVE-2022-30947 | 7.5 | N/A | Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file sy... |