Mozilla Bugzilla vulnerabilities
144 known vulnerabilities affecting mozilla/bugzilla.
Total CVEs
144
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17
Vulnerabilities
Page 1 of 8
CVE-2018-5123HIGHCVSS 8.8fixed in 4.4vAll versions prior to Bugzilla 4.42019-04-29
CVE-2018-5123 [HIGH] CWE-352 CVE-2018-5123: A third party website can access information available to a user with access to a restricted bug ent
A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.
cvelistv5nvd
CVE-2016-2803MEDIUMCVSS 6.1v2.2v2.4+200 more2017-04-12
CVE-2016-2803 [MEDIUM] CWE-79 CVE-2016-2803: Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11
Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2015-8508MEDIUMCVSS 4.7v2.0v2.2+145 more2016-01-03
CVE-2015-8508 [MEDIUM] CWE-79 CVE-2015-8508: Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x be
Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2, when a local dot configuration is used, allows remote attackers to inject arbitrary web script or HTML via a crafted bug summary.
nvd
CVE-2015-8509LOWCVSS 3.5v2.0v2.2+145 more2016-01-03
CVE-2015-8509 [LOW] CWE-200 CVE-2015-8509: Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x an
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.
nvd
CVE-2015-4499HIGHCVSS 7.5v2.0v2.2+184 more2015-09-14
CVE-2015-4499 [HIGH] CWE-20 CVE-2015-4499: Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5
Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.c
nvd
CVE-2014-8630MEDIUMCVSS 6.5≤ 4.0.16v4.1+33 more2015-02-01
CVE-2014-8630 [MEDIUM] CWE-77 CVE-2014-8630: Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
nvd
CVE-2014-1573MEDIUMCVSS 4.3v2.0v2.2+182 more2014-10-13
CVE-2014-1573 [MEDIUM] CWE-79 CVE-2014-1573: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
nvd
CVE-2014-1571MEDIUMCVSS 4.0v2.0v2.2+182 more2014-10-13
CVE-2014-1571 [MEDIUM] CWE-200 CVE-2014-1571: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.
nvd
CVE-2014-1572MEDIUMCVSS 5.0v2.0v2.2+182 more2014-10-13
CVE-2014-1572 [MEDIUM] CWE-264 CVE-2014-1572: The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x thr
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses
nvd
CVE-2014-1546MEDIUMCVSS 4.3v3.0v3.0.0+111 more2014-08-14
CVE-2014-1546 [MEDIUM] CWE-352 CVE-2014-1546: The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzil
The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct
nvd
CVE-2014-1517MEDIUMCVSS 4.0v2.0v2.2+180 more2014-04-20
CVE-2014-1517 [MEDIUM] CWE-287 CVE-2014-1517: The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly hand
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related
nvd
CVE-2013-1742MEDIUMCVSS 4.3PoCv4.1v4.1.1+168 more2013-10-24
CVE-2013-1742 [MEDIUM] CWE-79 CVE-2013-1742: Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) sortkey parameter.
nvd
CVE-2013-1743MEDIUMCVSS 4.3PoCv4.1v4.1.1+13 more2013-10-24
CVE-2013-1743 [MEDIUM] CVE-2013-1743: Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the (1) summary or (2) real name field. NOTE: this i
nvd
CVE-2013-1733MEDIUMCVSS 6.8v4.42013-10-24
CVE-2013-1733 [MEDIUM] CWE-352 CVE-2013-1733: Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 al
Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs via vectors involving a midair-collision token.
nvd
CVE-2013-1734MEDIUMCVSS 6.8v2.0v2.2+168 more2013-10-24
CVE-2013-1734 [MEDIUM] CWE-352 CVE-2013-1734: Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x be
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action.
nvd
CVE-2013-0786MEDIUMCVSS 5.0≤ 3.6.12v3.6+99 more2013-02-24
CVE-2013-0786 [MEDIUM] CWE-200 CVE-2013-0786: The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4
The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.
nvd
CVE-2013-0785MEDIUMCVSS 4.3≤ 3.6.12v3.6+40 more2013-02-24
CVE-2013-0785 [MEDIUM] CWE-79 CVE-2013-0785: Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x
Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before 4.2.5, and 4.3.x and 4.4.x before 4.4rc2 allows remote attackers to inject arbitrary web script or HTML via the id parameter in conjunction with an invalid value of the format parameter.
nvd
CVE-2012-4189MEDIUMCVSS 4.3v4.1v4.1.1+10 more2012-11-16
CVE-2012-4189 [MEDIUM] CWE-79 CVE-2012-4189: Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the Version field.
nvd
CVE-2012-4197MEDIUMCVSS 5.0v2.0v2.2+161 more2012-11-16
CVE-2012-4197 [MEDIUM] CWE-200 CVE-2012-4197: Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x befo
Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allows remote attackers to read attachment descriptions from private bugs via an obsolete=1 insert action.
nvd
CVE-2012-5884MEDIUMCVSS 5.0v4.3.22012-11-16
CVE-2012-5884 [MEDIUM] CVE-2012-5884: The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obta
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-2012-4198.
nvd
1 / 8Next →