Fossil Scm
fossil_scm
4 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly han...Show more |
2Fedoraproject Fossil Scm2Fedora FossilNov 21, 2024 Jul 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation. |
3Fedoraproject Fossil ScmOpensuse4Backports Sle FedoraFossil+1 moreNov 21, 2024 Aug 25, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository. |
http_transport.c in Fossil before 2.4, when the SSH sync protocol is used, allows user-assisted remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issu...Show more |