<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:18:16.762530+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-01486</id>
    <title>bdu:2018-01486</title>
    <updated>2026-10-03T07:18:16.781937+00:00</updated>
    <content>bdu:2018-01486</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-01486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-11235</id>
    <title>Withdrawn: BELL-CVE-2018-11235 — CVE-2018-11235 does not affect BellSoft software</title>
    <updated>2026-10-03T07:18:16.781976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-11235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-263</id>
    <title>certfr-2018-avi-263 — De multiples vulnérabilités ont été découvertes dans Git . Elles
permettent à un attaquant de provoquer une exécution d…</title>
    <updated>2026-10-03T07:18:16.781995+00:00</updated>
    <content>certfr-2018-avi-263</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-da54613</id>
    <title>CLEANSTART-2025-DA54613 — In Git before 2</title>
    <updated>2026-10-03T07:18:16.782010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: git</p>
<p>Security vulnerability affects the git package. In Git before 2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-da54613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-10794</id>
    <title>cnvd-2018-10794</title>
    <updated>2026-10-03T07:18:16.782038+00:00</updated>
    <content>cnvd-2018-10794</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-10794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-65114</id>
    <title>EUVD-2026-65114</title>
    <updated>2026-10-03T07:18:16.782051+00:00</updated>
    <content>EUVD-2026-65114</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-65114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-11235</id>
    <title>fkie_cve-2018-11235</title>
    <updated>2026-10-03T07:18:16.782061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-11235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v6w3-vcjx-mwhx</id>
    <title>GHSA-v6w3-vcjx-mwhx</title>
    <updated>2026-10-03T07:18:16.782085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v6w3-vcjx-mwhx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-11235</id>
    <title>gsd-2018-11235</title>
    <updated>2026-10-03T07:18:16.782103+00:00</updated>
    <content>gsd-2018-11235</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-11235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0598-1</id>
    <title>openSUSE-SU-2020:0598-1 — Security update for git</title>
    <updated>2026-10-03T07:18:16.782121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for git</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0598-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2147</id>
    <title>RHSA-2018:2147 — Red Hat Security Advisory: rh-git29-git security update</title>
    <updated>2026-10-03T07:18:16.782143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>git: path sanity check in is_ntfs_dotgit() can read arbitrary memory git: arbitrary code execution when recursively cloning a malicious repository</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:1566-1</id>
    <title>SUSE-SU-2018:1566-1 — Security update for git</title>
    <updated>2026-10-03T07:18:16.782160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for git</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:1566-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-11235</id>
    <title>UBUNTU-CVE-2018-11235</title>
    <updated>2026-10-03T07:18:16.782175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: git, Ubuntu:16.04:LTS: git, Ubuntu:18.04:LTS: git</p>
<p>In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-11235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-016</id>
    <title>VDE-2023-016 — Phoenix Contact: PLCnext Engineer Vulnerabilities in LibGit2Sharp/LibGit2</title>
    <updated>2026-10-03T07:18:16.782199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been discovered in the LibGit2Sharp or underlying LibGit2 library.This open-source component is widely used in a lot of products worldwide.The product is vulnerable to remote code execution, privilege escalation and tampering.PLCnext Engineer is using the LibGit2Sharp library to provide version control capabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-016"/>
  </entry>
</feed>
