Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mercurial MEDIUM 5.9
CVE-2010-4237

Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a …

Fix: 1.6.4+
Fix from $1,600 2019-10-29
Mercurial CRITICAL 9.1
CVE-2018-17983

cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.

Fix: 4.7.2+
Fix from $2,300 2018-10-04
Mercurial CRITICAL 9.8
CVE-2018-13347

mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.

Fix: 4.6.1+
Fix from $2,300 2018-07-06
Mercurial HIGH 7.5
CVE-2018-13346

The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the origina…

Fix: 4.6.1+
Fix from $1,950 2018-07-06
Mercurial HIGH 7.5
CVE-2018-13348

The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining afte…

Fix: 4.6.1+
Fix from $1,950 2018-07-06
Mercurial MEDIUM 5.0
CVE-2008-4297

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbit…

Fix: after 1.0.1
Fix from $1,600 2008-09-27
Mercurial MEDIUM 6.8
CVE-2008-2942

Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequence…

No fix yet
Fix from $1,600 2008-06-30