Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 19 of 19 results


CVE-2017-9462

Medium priority

Some fixes available 3 of 5

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Fixed
Show less packages

CVE-2016-3105

Medium priority

Some fixes available 2 of 4

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Fixed
Show less packages

CVE-2016-3630

Medium priority

Some fixes available 1 of 3

The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Not affected
Show less packages

CVE-2016-3069

Medium priority

Some fixes available 1 of 3

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Not affected
Show less packages

CVE-2016-3068

Medium priority

Some fixes available 1 of 3

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial Not affected Not affected
Show less packages

CVE-2014-9462

Medium priority

Some fixes available 4 of 5

The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial
Show less packages

CVE-2014-9390

Medium priority

Some fixes available 25 of 40

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...

5 affected packages

git, git-core, jgit, libgit2, mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
git Fixed Fixed Fixed Fixed Fixed
git-core Not in release Not in release Not in release Not in release Not in release
jgit Not affected Not affected Not affected Not affected Not affected
libgit2 Not affected Not affected Not affected Not affected Not affected
mercurial Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2008-4297

Negligible priority
Ignored

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial
Show less packages

CVE-2008-2942

Low priority
Ignored

Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.

1 affected packages

mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mercurial
Show less packages