Логотип exploitDog
bind: "CVE-2025-27614"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-27614"

Количество 13

Количество 13

ubuntu логотип

CVE-2025-27614

4 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2025-27614

4 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2025-27614

4 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2025-27614

4 месяца назад

GitHub: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability

EPSS: Низкий
debian логотип

CVE-2025-27614

4 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Gi ...

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2025-09363

4 месяца назад

Уязвимость команды gitk filename браузера Gitk, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03037-1

2 месяца назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03012-1

2 месяца назад

security update for git, git-lfs, obs-scm-bridge, python-PyYAML

EPSS: Низкий
rocky логотип

RLSA-2025:11534

3 месяца назад

Important: git security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11534

4 месяца назад

ELSA-2025-11534: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11533

4 месяца назад

ELSA-2025-11533: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-11462

4 месяца назад

ELSA-2025-11462: git security update (IMPORTANT)

EPSS: Низкий
redos логотип

ROS-20250807-04

3 месяца назад

Множественные уязвимости git

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-27614

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 8.6
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-27614

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 6.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-27614

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 8.6
0%
Низкий
4 месяца назад
msrc логотип
CVE-2025-27614

GitHub: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability

0%
Низкий
4 месяца назад
debian логотип
CVE-2025-27614

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Gi ...

CVSS3: 8.6
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-09363

Уязвимость команды gitk filename браузера Gitk, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 8.6
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03037-1

Security update for git

2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03012-1

security update for git, git-lfs, obs-scm-bridge, python-PyYAML

2 месяца назад
rocky логотип
RLSA-2025:11534

Important: git security update

3 месяца назад
oracle-oval логотип
ELSA-2025-11534

ELSA-2025-11534: git security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-11533

ELSA-2025-11533: git security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-11462

ELSA-2025-11462: git security update (IMPORTANT)

4 месяца назад
redos логотип
ROS-20250807-04

Множественные уязвимости git

CVSS3: 8.6
3 месяца назад

Уязвимостей на страницу