CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-53586 MEDIUM

libgit2: HTTP transport can leak credentials to an offsite redirect target

CVSS 6.5 EPSS 0.48% Aug 20, 2026
CVE-2026-53583 MEDIUM

libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend

CVSS 6.5 EPSS 0.24% Aug 20, 2026
CVE-2026-53585 MEDIUM

libgit2: Unbounded Memory Allocation via Delta Object Result-Size Header

CVSS 6.5 EPSS 0.55% Aug 20, 2026
CVE-2026-53587 HIGH

libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data

CVSS 7.5 EPSS 0.47% Aug 20, 2026
CVE-2026-53584 MEDIUM

libgit2: Submodule path traversal

CVSS 4.3 EPSS 0.41% Aug 20, 2026
CVE-2026-5917 HIGH

libgit2 Shell Command Injection via ssh_libssh2 Backend

CVSS 8.6 EPSS 1.43% Aug 11, 2026
CVE-2024-24577 CRITICAL

libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`

CVSS 9.8 EPSS 1.55% Feb 6, 2024
CVE-2024-24575 HIGH

libgit2 is vulnerable to a denial of service attack in `git_revparse_single`

CVSS 7.5 EPSS 1.44% Feb 6, 2024
CVE-2023-22742 MEDIUM

libgit2 fails to verify SSH keys by default

CVSS 5.9 EPSS 0.58% Jan 20, 2023
CVE-2020-12279 CRITICAL

libgit2: NTFS protections inactive when running Git in the Windows Subsystem for Linux

CVSS 9.8 EPSS 5.21% Apr 27, 2020
CVE-2020-12278 CRITICAL

libgit2: files inside the .git directory may be overwritten during cloning via NTFS Alternate Data Streams

CVSS 9.8 EPSS 5.24% Apr 27, 2020
CVE-2014-9390 CRITICAL

git: arbitrary command execution vulnerability on case-insensitive file systems

CVSS 9.3 EPSS 75.60% Feb 12, 2020
CVE-2018-15501 HIGH

libgit2: out-of-bounds reads when processing smart-protocol ng packets

CVSS 7.5 EPSS 4.37% Aug 18, 2018
CVE-2018-10888 MEDIUM

A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading…

CVSS 6.5 EPSS 1.85% Jul 10, 2018
CVE-2018-10887 HIGH

A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lea…

CVSS 8.1 EPSS 2.05% Jul 10, 2018
CVE-2018-8099 MEDIUM

libgit2: denial of service (DoS) via crafted repository index files

CVSS 6.5 EPSS 1.38% Mar 14, 2018
CVE-2018-8098 MEDIUM

libgit2: denial of service (DoS) via crafted repository index files

CVSS 6.5 EPSS 1.41% Mar 14, 2018
CVE-2016-10130 MEDIUM

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by le…

CVSS 5.9 EPSS 1.72% Mar 24, 2017
CVE-2016-10129 HIGH

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference…

CVSS 7.5 EPSS 3.64% Mar 24, 2017
CVE-2016-10128 CRITICAL

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.…

CVSS 9.8 EPSS 3.96% Mar 24, 2017
CVE-2016-8569 MEDIUM

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file c…

CVSS 5.5 EPSS 1.84% Feb 3, 2017
CVE-2016-8568 MEDIUM

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file comm…

CVSS 5.5 EPSS 1.90% Feb 3, 2017

Showing 1 to 22 CVEs · page 1