CVE-2009-3386
published 2009-11-20CVE-2009-3386: Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.73%
75.2th percentile
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-50228 [MEDIUM] kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0
kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0
Don't BUG/WARN on interrupt injection due to GIF being cleared,
since it's trivial for userspace to force the situation via
KVM_SET_VCPU_EVENTS (even if having at least a WARN there would be correct
for KVM internally generated injections).
kernel BUG at arch/x86/kvm/svm/svm.c:3386!
invalid opcode: 0000 [#1] SMP
CPU: 15 PID: 926 Comm: smm_test Not tainted 5.17.0-rc3+ #264
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
RIP: 0010:svm_inject_irq+0xab/0xb0 [kvm_amd]
Code: 0b 0f 1f 00 0f 1f 44 00 00 80 3d ac b3 01 00 00 55 48 89 f5 53
RSP: 0018:ffffc90000b37d88 EFL
Red Hat
bugzilla hidden bug alias disclosure
vendor_redhat·2009-11-18·CVSS 5.0
CVE-2009-3386 [MEDIUM] bugzilla hidden bug alias disclosure
bugzilla hidden bug alias disclosure
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
GHSA
GHSA-xf88-gp54-xgc2: Template
ghsa_unreviewed·2022-05-02
CVE-2009-3386 [MEDIUM] CWE-200 GHSA-xf88-gp54-xgc2: Template
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure
bugzilla·2009-11-20·CVSS 5.0
CVE-2009-3386 [MEDIUM] CVE-2009-3386 bugzilla hidden bug alias disclosure
CVE-2009-3386 bugzilla hidden bug alias disclosure
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1
allows remote attackers to discover the alias of a private bug by
reading the (1) Depends On or (2) Blocks field of a related bug.
http://www.bugzilla.org/security/3.4.3/
https://bugzilla.mozilla.org/show_bug.cgi?id=529416
http://secunia.com/advisories/37423
Discussion:
Created bugzilla tracking bugs for this issue
CVE-2009-3386 Affects: F11 [bug #539599]
CVE-2009-3386 Affects: F12 [bug #539600]
CVE-2009-3386 Affects: Fdevel [bug #539601]
---
Upstream advisory says it only affects 3.3.2 and later. As F11 is on 3.2.5 now, it should not be affected.
Rawhide already has 3.4.4 and F12 update was already submitted:
https://admin.fedoraproject.org/updates/bugzilla-3.4.4-1.
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure [Fdevel]
bugzilla·2009-11-20·CVSS 5.0
CVE-2009-3386 [MEDIUM] CVE-2009-3386 bugzilla hidden bug alias disclosure [Fdevel]
CVE-2009-3386 bugzilla hidden bug alias disclosure [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure [F11]
bugzilla·2009-11-20·CVSS 5.0
CVE-2009-3386 [MEDIUM] CVE-2009-3386 bugzilla hidden bug alias disclosure [F11]
CVE-2009-3386 bugzilla hidden bug alias disclosure [F11]
F11 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2011&bugs=539599,
---
As noted in the tracker bug, F11 has Bugzilla 3.2.5, which is not affected.
Bugzilla
CVE-2009-3386 bugzilla hidden bug alias disclosure [F12]
bugzilla·2009-11-20·CVSS 5.0
CVE-2009-3386 [MEDIUM] CVE-2009-3386 bugzilla hidden bug alias disclosure [F12]
CVE-2009-3386 bugzilla hidden bug alias disclosure [F12]
F12 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2012&bugs=539600,
---
I've received mail that bugzilla-3.4.4-1.fc12 has been pushed to updates.
The updates fixes this bug.
---
bugzilla-3.4.4-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-3014 firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links
bugzilla·2009-08-31·CVSS 4.3
CVE-2009-3014 [MEDIUM] CVE-2009-3014 firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links
CVE-2009-3014 firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3014 to
the following vulnerability:
Name: CVE-2009-3014
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3014
Assigned: 20090831
Reference: BUGTRAQ:20090828 Cross-Site Scripting vulnerability in Mozilla, Firefox, SeaMonkey, Orca Browser and Maxthon
Reference: URL: http://www.securityfocus.com/archive/1/archive/1/506163/100/0/threaded
Reference: MISC: http://websecurity.com.ua/3373/
Reference: MISC: http://websecurity.com.ua/3386/
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre;
SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle
javascript: URIs in HTML links within 302
Bugzilla
CVE-2009-3010 firefox/seamonkey: XSS due to data: URIs in refresh header
bugzilla·2009-08-31·CVSS 4.3
CVE-2009-3010 [MEDIUM] CVE-2009-3010 firefox/seamonkey: XSS due to data: URIs in refresh header
CVE-2009-3010 firefox/seamonkey: XSS due to data: URIs in refresh header
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3010 to
the following vulnerability:
Name: CVE-2009-3010
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3010
Assigned: 20090831
Reference: MISC: http://websecurity.com.ua/3315/
Reference: MISC: http://websecurity.com.ua/3386/
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre;
SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block
data: URIs in Refresh headers in HTTP responses, which allows remote
attackers to conduct cross-site scripting (XSS) attacks via vectors
related to (1) injecting a Refresh header that contains JavaScript
sequences in a data:text/html URI or (2) entering a data:text/html URI
wi
Bugzilla
CVE-2009-3012 firefox: xss due to data: URIs in Location header
bugzilla·2009-08-31·CVSS 4.3
CVE-2009-3012 [MEDIUM] CVE-2009-3012 firefox: xss due to data: URIs in Location header
CVE-2009-3012 firefox: xss due to data: URIs in Location header
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3012 to
the following vulnerability:
Name: CVE-2009-3012
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3012
Assigned: 20090831
Reference: MISC: http://websecurity.com.ua/3323/
Reference: MISC: http://websecurity.com.ua/3386/
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre
does not properly block data: URIs in Location headers in HTTP
responses, which allows remote attackers to conduct cross-site
scripting (XSS) attacks via vectors related to (1) injecting a
Location header that contains JavaScript sequences in a data:text/html
URI or (2) entering a data:text/html URI with JavaScript sequences
when specifying the content of
http://osvdb.org/60271http://secunia.com/advisories/37423http://www.bugzilla.org/security/3.4.3/http://www.securityfocus.com/bid/37062http://www.vupen.com/english/advisories/2009/3288https://bugzilla.mozilla.org/show_bug.cgi?id=529416https://exchange.xforce.ibmcloud.com/vulnerabilities/54332http://osvdb.org/60271http://secunia.com/advisories/37423http://www.bugzilla.org/security/3.4.3/http://www.securityfocus.com/bid/37062http://www.vupen.com/english/advisories/2009/3288https://bugzilla.mozilla.org/show_bug.cgi?id=529416https://exchange.xforce.ibmcloud.com/vulnerabilities/54332
2009-11-20
Published