CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Git allows arbitrary code execution through broken config quoting
Git alllows arbitrary file writes via bundle-uri parameter injection
Git allows a buffer overflow in 'wincred' credential helper
The sideband payload is passed unfiltered to the terminal in git
Git does not sanitize URLs when asking for credentials interactively
Newline confusion in credential helpers can lead to credential exfiltration in git
All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of th…
Git's protections for cloning untrusted repositories can be bypassed
Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory
Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will
Git vulnerable to Remote Code Execution while cloning special-crafted local repositories
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
Arbitrary configuration injection via `git submodule deinit`
"git apply --reject" partially-controlled arbitrary file write
Git's `git apply` overwriting paths outside the working tree
Git vulnerable to local clone-based data exfiltration with non-local transports
gitattributes parsing integer overflow in git
Integer overflow in `git archive`, `git log --format` leading to RCE in git
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
Git subject to exposure of sensitive information via local clone of symbolic links
Bypass of safe.directory protections in Git
Command Injection
Remote Code Execution (RCE)
malicious repositories can execute remote code while cloning
Malicious URLs can still cause Git to send a stored credential to the wrong server
Showing 1 to 25 CVEs · page 1 (more available)