Search CVE reports


Toggle filters

1501 – 1510 of 1538 results


CVE-2017-8778

Medium priority
Ignored

GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2017-5339

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2
Show less packages

CVE-2017-5338

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2
Show less packages

CVE-2017-0882

Medium priority
Ignored

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2016-9469

Medium priority
Ignored

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2016-10130

Medium priority
Vulnerable

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-10129

Medium priority
Vulnerable

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-10128

Medium priority
Vulnerable

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted...

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2014-9938

Medium priority
Fixed

contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.

1 affected package

git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
git
Show less packages

CVE-2016-8569

Low priority

Some fixes available 2 of 5

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected
Show less packages