Search CVE reports
11 – 19 of 19 results
CVE-2017-9462
Medium prioritySome fixes available 3 of 5
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | Not affected | Fixed |
CVE-2016-3105
Medium prioritySome fixes available 2 of 4
The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | Not affected | Fixed |
CVE-2016-3630
Medium prioritySome fixes available 1 of 3
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | Not affected | Not affected |
CVE-2016-3069
Medium prioritySome fixes available 1 of 3
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | Not affected | Not affected |
CVE-2016-3068
Medium prioritySome fixes available 1 of 3
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | Not affected | Not affected |
CVE-2014-9462
Medium prioritySome fixes available 4 of 5
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | — | — |
CVE-2014-9390
Medium prioritySome fixes available 26 of 41
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...
5 affected packages
git, git-core, jgit, libgit2, mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
git | Fixed | Fixed | Fixed | Fixed | Fixed |
git-core | Not in release | Not in release | Not in release | Not in release | Not in release |
jgit | Not affected | Not affected | Not affected | Not affected | Not affected |
libgit2 | Not affected | Not affected | Not affected | Not affected | Not affected |
mercurial | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2008-4297
Negligible priorityMercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | — | — |
CVE-2008-2942
Low priorityDirectory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
1 affected package
mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mercurial | — | — | — | — | — |