Skip to main content

Vendor/product archive

mozilla / bugzilla CVEs

Beta · best-effort

151 CVEs tagged to mozilla / bugzilla4 Critical, 36 High, 94 Medium, 17 Low, 0 Unrated.

CVE-2012-1969

Published Jul 30, 2012

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1968

Published Jul 30, 2012

Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, whic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0466

Published Apr 27, 2012

template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0465

Published Apr 27, 2012

Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0453

Published Feb 25, 2012

Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack th…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0448

Published Feb 2, 2012

Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail ad…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0440

Published Feb 2, 2012

Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows rem…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3669

Published Jan 2, 2012

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3668

Published Jan 2, 2012

Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3667

Published Jan 2, 2012

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3657

Published Jan 2, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, whe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2979

Published Aug 9, 2011

Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2978

Published Aug 9, 2011

Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2977

Published Aug 9, 2011

Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows lo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2976

Published Aug 9, 2011

Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2381

Published Aug 9, 2011

CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2380

Published Aug 9, 2011

Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7292

Published Aug 9, 2011

Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0048

Published Jan 28, 2011

Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_l…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0046

Published Jan 28, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4572

Published Jan 28, 2011

CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4570

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4569

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a us…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4568

Published Jan 28, 2011

Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 151 CVEsPage 2 of 7