Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mercurial mercurial vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2017-18026
Redmine prior to 3.2.9, 3.3.x prior to 3.3.6, and 3.4.x prior to 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote malicious users to execute arbitrary commands (through the Mercurial adapter) via vectors involving a branch wh...
Redmine Redmine
Debian Debian Linux 9.0
8.8
CVSSv3
CVE-2017-17536
Phabricator prior to 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote malicious users to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.
Phacility Phabricator
8.8
CVSSv3
CVE-2016-3105
The convert extension in Mercurial prior to 3.8 might allow context-dependent malicious users to execute arbitrary code via a crafted git repository name.
Debian Debian Linux 8.0
Mercurial Mercurial
8.8
CVSSv3
CVE-2016-3630
The binary delta decoder in Mercurial prior to 3.7.3 allows remote malicious users to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Fedoraproject Fedora 22
Fedoraproject Fedora 23
Opensuse Leap 42.1
Mercurial Mercurial
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Suse Linux Enterprise Software Development Kit 12
Suse Linux Enterprise Software Development Kit 11
Suse Linux Enterprise Debuginfo 11
Opensuse Opensuse 13.2
8.1
CVSSv3
CVE-2018-13386
There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Ve...
Atlassian Sourcetree
7.5
CVSSv3
CVE-2022-30948
Jenkins Mercurial Plugin 2.16 and previous versions allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM cont...
Jenkins Mercurial
7.5
CVSSv3
CVE-2018-13346
The mpatch_apply function in mpatch.c in Mercurial prior to 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
Mercurial Mercurial
7.5
CVSSv3
CVE-2018-13348
The mpatch_decode function in mpatch.c in Mercurial prior to 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.
Mercurial Mercurial
7.2
CVSSv3
CVE-2018-5223
Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice on...
Atlassian Fisheye
Atlassian Crucible
6.5
CVSSv3
CVE-2020-2305
Jenkins Mercurial Plugin 2.11 and previous versions does not configure its XML parser to prevent XML external entity (XXE) attacks.
Jenkins Mercurial
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »