Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mercurial mercurial vulnerabilities and exploits
(subscribe to this query)
516
VMScore
CVE-2019-3902
A flaw was found in Mercurial prior to 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
Mercurial Mercurial
Redhat Enterprise Linux 7.0
Debian Debian Linux 8.0
445
VMScore
CVE-2022-30948
Jenkins Mercurial Plugin 2.16 and previous versions allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM cont...
Jenkins Mercurial
445
VMScore
CVE-2018-13346
The mpatch_apply function in mpatch.c in Mercurial prior to 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
Mercurial Mercurial
445
VMScore
CVE-2018-13348
The mpatch_decode function in mpatch.c in Mercurial prior to 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.
Mercurial Mercurial
445
VMScore
CVE-2018-1000112
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and previous versions in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Jenkins Mercurial
445
VMScore
CVE-2008-4297
Mercurial prior to 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote malicious users to read arbitrary files from a repository via an "hg pull" request.
Mercurial Mercurial
383
VMScore
CVE-2010-4237
Mercurial prior to 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-middle attack.
Mercurial Mercurial
356
VMScore
CVE-2020-2305
Jenkins Mercurial Plugin 2.11 and previous versions does not configure its XML parser to prevent XML external entity (XXE) attacks.
Jenkins Mercurial
356
VMScore
CVE-2020-2306
A missing permission check in Jenkins Mercurial Plugin 2.11 and previous versions allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
Jenkins Mercurial
NA
CVE_2022_40684
Official Writeup - Simple CTF 2.0 Created: April 23, 2024 7:50 PM Today I completed an other room on TryHackMe with a simple file-upload vulnerability which I built. I have tried for dancing around this whole CTF machine and getting a lot of walls of challenges in the end it co...
1 Github repository
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »