Skip to main content

Vendor/product archive

mozilla / bugzilla CVEs

Beta · best-effort

151 CVEs tagged to mozilla / bugzilla4 Critical, 36 High, 94 Medium, 17 Low, 0 Unrated.

CVE-2010-4567

Published Jan 28, 2011

Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which al…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4209

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4208

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4207

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3764

Published Nov 5, 2010

The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3172

Published Nov 5, 2010

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2759

Published Aug 16, 2010

Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2)…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2758

Published Aug 16, 2010

Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which make…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2757

Published Aug 16, 2010

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2756

Published Aug 16, 2010

Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2470

Published Jun 28, 2010

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, whi…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1204

Published Jun 28, 2010

Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0180

Published Jun 28, 2010

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to rea…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3989

Published Feb 3, 2010

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3387

Published Feb 3, 2010

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3386

Published Nov 20, 2009

Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3166

Published Sep 15, 2009

token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-depe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3165

Published Sep 15, 2009

SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3125

Published Sep 15, 2009

SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1213

Published Apr 1, 2009

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6098

Published Feb 9, 2009

Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to ap…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0486

Published Feb 9, 2009

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficien…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0485

Published Feb 9, 2009

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0484

Published Feb 9, 2009

Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete shared or saved searches via…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0483

Published Feb 9, 2009

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 151 CVEsPage 3 of 7