Lars Hjemli maintains cgit, a lightweight web interface for Git repositories commonly deployed in code-hosting and development infrastructure environments. The vulnerability surface centers on web-facing input handling and memory management, with recurring issues including path traversal, cross-site scripting, buffer-boundary errors, and off-by-one conditions typical of a C-based web application. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lars Hjemli over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4465MEDIUM Heap-based buffer overflow in the substr function in parsing.c in cgit 0.9.0.3 and earlier allows remote authenticated users to cause a denial of service (crash) and possibly execu | Oct 10, 2012 | 6.5 | 22 | NO | NO |
CVE-2012-4548MEDIUM Argument injection vulnerability in syntax-highlighting.sh in cgit 9.0.3 and earlier allows remote authenticated users with permissions to add files to execute arbitrary commands v | Nov 11, 2012 | 6.0 | 20 | NO | NO |
CVE-2011-1027MEDIUM Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a strin | Mar 20, 2011 | 5.0 | 20 | NO | NO |
Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or | Aug 3, 2011 | 3.5 | 15 | NO | NO |
CVE-2013-2117MEDIUM Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to | Aug 9, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lars Hjemli.
Media articles that mention a CVE ID that affects a product developed by Lars Hjemli — matched by CVE ID, not by vendor name.