dulwich_project CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

dulwich_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all dulwich_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk buffer overflow; exposure may include vendor impact application crash and vendor impact memory corruption in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2017-16228 Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117. [email protected] 9.8 0.42% 2017-10-29 2026-05-13
CVE-2015-0838 Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file. [email protected] 7.5 2.81% 2015-03-31 2026-05-06
CVE-2014-9706 The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree. [email protected] 7.5 2.77% 2015-03-31 2026-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence