Skip to main content

Vendor/product archive

mozilla / bugzilla CVEs

Beta · best-effort

151 CVEs tagged to mozilla / bugzilla4 Critical, 36 High, 94 Medium, 17 Low, 0 Unrated.

CVE-2018-5123

Published Apr 29, 2019

A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2803

Published Apr 12, 2017

Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web scrip…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8509

Published Jan 3, 2016

Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-8508

Published Jan 3, 2016

Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2, w…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4499

Published Sep 14, 2015

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows…

CVSS 7.5 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2014-8630

Published Feb 1, 2015

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by lever…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1573

Published Oct 13, 2014

Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for cer…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1572

Published Oct 13, 2014

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-1571

Published Oct 13, 2014

Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1546

Published Aug 14, 2014

The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x be…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1517

Published Apr 20, 2014

The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easie…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1743

Published Oct 24, 2013

Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1742

Published Oct 24, 2013

Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1734

Published Oct 24, 2013

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 all…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1733

Published Oct 24, 2013

Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for reque…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0786

Published Feb 24, 2013

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0785

Published Feb 24, 2013

Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before 4.2.5, and 4.3.x and 4.4.x before 4.4rc2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5884

Published Nov 16, 2012

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XML…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5883

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4199

Published Nov 16, 2012

template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4198

Published Nov 16, 2012

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcom…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4197

Published Nov 16, 2012

Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allow…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4189

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4747

Published Sep 4, 2012

Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3981

Published Sep 4, 2012

Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 151 CVEsPage 1 of 7