Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the… | |
| Pendiente de análisis | Media (6.5) | 0.48% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite initial redirect, and handle_remote_auth… | |
| Pendiente de análisis | Media (5.3) | 0.55% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value parsed by hdr_sz from a delta object… | |
| Pendiente de análisis | Media (4.3) | 0.41% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from .gitmodules. The affected… | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when… | |
| Aplazada | Alta (8.6) | 1.4% | — | Libgit2AILibssh2AI | 11/8/2026 | 24/9/2026 | libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single… | |
| Modificada | Crítica (9.8) | 1.5% | — | Libgit2 | 6/2/2024 | 17/6/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary code execution. There is an issue in… | |
| Modificada | Alta (7.5) | 1.4% | — | Libgit2 | 6/2/2024 | 17/6/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop, potentially causing a Denial of Service attack… | |
| Modificada | Media (5.9) | 0.58% | — | Libgit2 | 20/1/2023 | 17/6/2026 | libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if… | |
| Modificada | Crítica (9.8) | 5.2% | — | Libgit2Debian Linux | 27/4/2020 | 17/6/2026 | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353. | |
| Modificada | Crítica (9.8) | 5.2% | — | Libgit2Debian Linux | 27/4/2020 | 17/6/2026 | An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352. | |
| Modificada | Crítica (9.8) | 76% | — | Git-scm GITMercurialApple XcodeEclipse Egit+2 | 12/2/2020 | 17/6/2026 | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit… | |
| Modificada | Alta (7.5) | 4.4% | — | Debian LinuxLibgit2 | 18/8/2018 | 17/6/2026 | In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS. | |
| Modificada | Media (6.5) | 1.8% | — | Libgit2Debian Linux | 10/7/2018 | 17/6/2026 | A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading a binary delta file. An attacker may use this flaw to cause a Denial of Service. | |
| Modificada | Alta (8.1) | 2.1% | — | Libgit2Debian Linux | 10/7/2018 | 17/6/2026 | A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing to read before the base object. An attacker may use this flaw to leak memory… | |
| Modificada | Media (6.5) | 1.4% | — | Libgit2Debian Linux | 14/3/2018 | 17/6/2026 | Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file. | |
| Modificada | Media (6.5) | 1.4% | — | Libgit2Debian Linux | 14/3/2018 | 17/6/2026 | Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file. | |
| Modificada | Media (5.9) | 1.7% | — | Libgit2 Project Libgit2 | 24/3/2017 | 17/6/2026 | The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable. | |
| Modificada | Alta (7.5) | 3.6% | — | Libgit2 Project Libgit2 | 24/3/2017 | 17/6/2026 | The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line. | |
| Modificada | Crítica (9.8) | 4.0% | — | Libgit2 Project Libgit2 | 24/3/2017 | 17/6/2026 | Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet. | |
| Modificada | Media (5.5) | 1.8% | — | Libgit2 Project Libgit2Fedoraproject FedoraOpensuse LeapOpensuse+1 | 3/2/2017 | 17/6/2026 | The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file. | |
| Modificada | Media (5.5) | 1.9% | — | Fedoraproject FedoraOpensuse LeapOpensuseSuse Linux Enterprise+1 | 3/2/2017 | 17/6/2026 | The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file. |