Search CVE reports


Toggle filters

11 – 19 of 19 results


CVE-2017-9462

Medium priority

Some fixes available 3 of 5

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Fixed
Show less packages

CVE-2016-3105

Medium priority

Some fixes available 2 of 4

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Fixed
Show less packages

CVE-2016-3630

Medium priority

Some fixes available 1 of 3

The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Not affected
Show less packages

CVE-2016-3069

Medium priority

Some fixes available 1 of 3

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Not affected
Show less packages

CVE-2016-3068

Medium priority

Some fixes available 1 of 3

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Not affected
Show less packages

CVE-2014-9462

Medium priority

Some fixes available 4 of 5

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial
Show less packages

CVE-2014-9390

Medium priority

Some fixes available 26 of 41

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...

5 affected packages

git, git-core, jgit, libgit2, mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
git Fixed Fixed Fixed Fixed Fixed
git-core Not in release Not in release Not in release Not in release Not in release
jgit Not affected Not affected Not affected Not affected Not affected
libgit2 Not affected Not affected Not affected Not affected Not affected
mercurial Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2008-4297

Negligible priority
Ignored

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial
Show less packages

CVE-2008-2942

Low priority
Ignored

Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.

1 affected package

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial
Show less packages