Skip to main content

Vendor/product archive

lars_hjemli / cgit CVEs

Beta · best-effort

5 CVEs tagged to lars_hjemli / cgit0 Critical, 0 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2013-2117

Published Aug 9, 2013

Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4548

Published Nov 11, 2012

Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4465

Published Oct 10, 2012

Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly exec…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2711

Published Aug 3, 2011

Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script o…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1027

Published Mar 20, 2011

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a stri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1