Libgit2-project
5 CVEs tracked since 2017. Since Feb 2017, none of them reached CISA KEV.
Libgit2-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-02 | 2 | 0 |
| 2017-03 | 3 | 0 |
Products
The products that kept showing up in Libgit2-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Libgit2-project.
- CVE-2016-10129The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.7.5
- CVE-2016-10130The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error varia...5.9
- CVE-2016-10128Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unsp...9.8
- CVE-2016-8568The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.5.5
- CVE-2016-8569The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.5.5
The record
- Peak rank
- #104 in Feb 2017
- Busiest month shown
- Mar 2017, 3 CVEs
- Months with a KEV entry
- 0 since Feb 2017
- Monthly snapshots
- 2 since 2017