Show filters
52 Total Results
Displaying 31-40 of 52
Sort by:
Attacker Value
Unknown

CVE-2014-9462

Disclosure Date: March 31, 2015 (last updated October 05, 2023)
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
0
Attacker Value
Unknown

CVE-2012-4999

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) If-Modified-Since, (2) If-None-Match, or (3) If-Unmodified-Since. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-4755

Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.
0
Attacker Value
Unknown

CVE-2009-4754

Disclosure Date: March 29, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file.
0
Attacker Value
Unknown

CVE-2008-7011

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.
0
Attacker Value
Unknown

CVE-2008-6632

Disclosure Date: April 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
0
Attacker Value
Unknown

CVE-2008-4297

Disclosure Date: September 27, 2008 (last updated October 04, 2023)
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
0
Attacker Value
Unknown

CVE-2008-2942

Disclosure Date: June 30, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.
0
Attacker Value
Unknown

CVE-2008-0757

Disclosure Date: February 13, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-3669

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.
0