Vulnerabilities

Last updated 2 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
dulwich Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths High Risk 8.8 7 hours ago 6 hours ago
dulwich Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution Medium Risk 6.5 7 hours ago 7 hours ago
dulwich Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence High Risk 8.6 7 hours ago 7 hours ago
dulwich Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections High Risk 8.6 7 hours ago 7 hours ago
dulwich Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks High Risk 8.6 7 hours ago 7 hours ago
dulwich Dulwich Vulnerable to Command Injection via Merge Driver Path High Risk 8.0 4 months ago 22 days ago
dulwich Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows High Risk 8.8 4 months ago 22 days ago
dulwich Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` Low Risk 3.3 3 months ago 2 months ago
dulwich Dulwich has unbounded memory allocation in receive-pack from crafted thin packs Medium Risk 5.7 3 months ago 2 months ago
dulwich Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload High Risk 7.5 3 months ago 2 months ago
dulwich Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` Low Risk 3.3 2 months ago 2 months ago
dulwich Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows High Risk 8.8 2 months ago 2 months ago
dulwich Dulwich Vulnerable to Command Injection via Merge Driver Path Unknown 2 months ago 2 months ago
dulwich Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload High Risk 7.5 2 months ago 2 months ago
dulwich Dulwich has unbounded memory allocation in receive-pack from crafted thin packs Medium Risk 5.7 2 months ago 2 months ago
dulwich No summary available Unknown 11 years ago 3 months ago
dulwich No summary available Unknown 8 years ago 3 months ago
dulwich No summary available Unknown 11 years ago 3 months ago
dulwich Dulwich Arbitrary code execution via commit with directory path starting with .git Critical 9.8 4 years ago 4 months ago
dulwich Dulwich Buffer Overflow when handling pack files Critical 9.8 4 years ago 1 year ago
dulwich Dulwich RCE Vulnerability Critical 9.8 4 years ago 1 year ago