Show filters
79 Total Results
Displaying 11-20 of 79
Sort by:
Attacker Value
Unknown
CVE-2021-23241
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
0
Attacker Value
Unknown
CVE-2020-2306
Disclosure Date: November 04, 2020 (last updated October 26, 2023)
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
0
Attacker Value
Unknown
CVE-2020-2305
Disclosure Date: November 04, 2020 (last updated October 26, 2023)
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2020-10990
Disclosure Date: March 27, 2020 (last updated February 21, 2025)
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.
0
Attacker Value
Unknown
CVE-2014-9390
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
0
Attacker Value
Unknown
CVE-2010-4237
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2019-3902
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
0
Attacker Value
Unknown
CVE-2018-17983
Disclosure Date: October 04, 2018 (last updated November 27, 2024)
cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
0
Attacker Value
Unknown
CVE-2018-13347
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.
0
Attacker Value
Unknown
CVE-2018-13346
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
0