-Infinity
0

Vendor Risk Score

See how cvs compares to other vendors in security performance

View Risk Score →

Software

CVS CVSCommand Injection

Risk 18
Severity
4
First published (updated )

CVS CVSBuffer Overflow

Risk 89
Severity
10
First published (updated )

CVS CVS clientWhen correcting a crash in CVS [1] it was found that the CVS client suffers from a flaw that causes …

Risk 18
Severity
4
First published (updated )

CVS CVScvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to ov…

Risk 34
Severity
4.6
First published (updated )

CVS CVSCVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to b…

Risk 52
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CVS CVSBuffer Overflow

Risk 52
Severity
7.5
First published (updated )

FreeBSD FreeBSDFormat string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 al…

Risk 62
Severity
7.1
First published (updated )

CVS CVSCVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current rep…

Risk 26
Severity
5
First published (updated )

CVS CVSCVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existe…

Risk 26
Severity
5
First published (updated )

CVS CVSBuffer Overflow, Double Free

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CVS CVSInteger Overflow

Risk 26
Severity
5
First published (updated )

CVS CVSCVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" li…

Risk 87
Severity
10
First published (updated )

CVS CVSserve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empt…

Risk 87
Severity
10
First published (updated )

CVS CVSBuffer Overflow

Risk 52
Severity
7.5
First published (updated )

CVS CVSCVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames v…

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CVS CVSThe client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using …

Risk 15
Severity
2.6
First published (updated )

CVS CVSCVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and file…

Risk 52
Severity
7.5
First published (updated )

CVS CVSDouble Free

Risk 52
Severity
7.5
First published (updated )

CVS CVSCVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to c…

Risk 26
Severity
5
First published (updated )

CVS CVSThe CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server …

Risk 13
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CVS CVSThe CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Updat…

Risk 63
Severity
7.2
First published (updated )

CVS CVSConcurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows l…

Risk 32
Severity
5.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203