Show filters
79 Total Results
Displaying 31-40 of 79
Sort by:
Attacker Value
Unknown
CVE-2016-3069
Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
0
Attacker Value
Unknown
CVE-2014-9462
Disclosure Date: March 31, 2015 (last updated October 05, 2023)
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
0
Attacker Value
Unknown
CVE-2010-1959
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-6632
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
0
Attacker Value
Unknown
CVE-2007-5289
Disclosure Date: February 24, 2009 (last updated October 04, 2023)
HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file's properties to read-only.
0
Attacker Value
Unknown
CVE-2008-4297
Disclosure Date: September 27, 2008 (last updated October 04, 2023)
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
0
Attacker Value
Unknown
CVE-2008-2942
Disclosure Date: June 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
0
Attacker Value
Unknown
CVE-2008-0757
Disclosure Date: February 13, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-5018
Disclosure Date: September 20, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
0
Attacker Value
Unknown
CVE-2007-4440
Disclosure Date: August 21, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
0