cbcvebase.

Mozilla Bugzilla vulnerabilities

144 known vulnerabilities affecting mozilla/bugzilla.

Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17

Vulnerabilities

Page 1 of 8
CVE-2008-4437P3HIGHCVSS 7.1PoCv2.4v2.6+16 more2008-10-03
CVE-2008-4437 [HIGH] CWE-22 CVE-2008-4437: Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, w Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
nvd
CVE-2001-0329P3HIGHCVSS 7.5PoCv2.4v2.6+2 more2001-06-27
CVE-2001-0329 [HIGH] CVE-2001-0329: Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a us Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.
nvd
CVE-2013-1743P4MEDIUMCVSS 4.3PoCv4.1v4.1.1+13 more2013-10-24
CVE-2013-1743 [MEDIUM] CVE-2013-1743: Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the (1) summary or (2) real name field. NOTE: this i
nvd
CVE-2013-1742P4MEDIUMCVSS 4.3PoCv4.1v4.1.1+168 more2013-10-24
CVE-2013-1742 [MEDIUM] CWE-79 CVE-2013-1742: Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4 Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) sortkey parameter.
nvd
CVE-2015-4499P3HIGHCVSS 7.5v2.0v2.2+184 more2015-09-14
CVE-2015-4499 [HIGH] CWE-20 CVE-2015-4499: Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5 Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.c
nvd
CVE-2009-3165P3HIGHCVSS 7.5v2.23.4v3.0+23 more2009-09-15
CVE-2009-3165 [HIGH] CWE-89 CVE-2009-3165: SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
nvd
CVE-2010-4568P3HIGHCVSS 7.5v2.14v2.14.1+97 more2011-01-28
CVE-2010-4568 [HIGH] CWE-264 CVE-2010-4568: Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x befo Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand functi
nvd
CVE-2009-3125P3HIGHCVSS 7.5v3.3.2v3.3.3+4 more2009-09-15
CVE-2009-3125 [HIGH] CWE-89 CVE-2009-3125: SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, a SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
nvd
CVE-2018-5123P3HIGHCVSS 8.8fixed in 4.4vAll versions prior to Bugzilla 4.42019-04-29
CVE-2018-5123 [HIGH] CWE-352 CVE-2018-5123: A third party website can access information available to a user with access to a restricted bug ent A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.
nvd
CVE-2003-1042P3CRITICALCVSS 10.0v2.4v2.6+16 more2004-08-18
CVE-2003-1042 [CRITICAL] CVE-2003-1042: SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authent SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.
nvd
CVE-2014-8630P3MEDIUMCVSS 6.5≤ 4.0.16v4.1+33 more2015-02-01
CVE-2014-8630 [MEDIUM] CWE-77 CVE-2014-8630: Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
nvd
CVE-2012-4189P4MEDIUMCVSS 4.3PoCv4.1v4.1.1+10 more2012-11-16
CVE-2012-4189 [MEDIUM] CWE-79 CVE-2012-4189: Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4 Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the Version field.
nvd
CVE-2003-1043P3CRITICALCVSS 10.0v2.4v2.6+16 more2004-08-18
CVE-2003-1043 [CRITICAL] CVE-2003-1043: SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.
nvd
CVE-2007-5038P3HIGHCVSS 7.5v3.0.0v3.0.1+2 more2007-09-24
CVE-2007-5038 [HIGH] CWE-264 CVE-2007-5038: The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1. The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
nvd
CVE-2007-0792P3HIGHCVSS 7.5v2.23.32007-02-06
CVE-2007-0792 [HIGH] CVE-2007-0792: The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
nvd
CVE-2002-0007P4CRITICALCVSS 10.0≤ 2.14.12002-01-31
CVE-2002-0007 [CRITICAL] CVE-2002-0007: CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bi CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.
nvd
CVE-2004-0707P4HIGHCVSS 7.5v2.4v2.6+22 more2004-07-27
CVE-2004-0707 [HIGH] CVE-2004-0707: SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18r SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.
nvd
CVE-2002-0010P4HIGHCVSS 7.5≤ 2.14.12002-01-31
CVE-2002-0010 [HIGH] CVE-2002-0010: Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value paramet
nvd
CVE-2007-4538P4MEDIUMCVSS 5.0v2.4v2.6+4 more2007-08-27
CVE-2007-4538 [MEDIUM] CVE-2007-4538: email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands v email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.
nvd
CVE-2006-0915P4HIGHCVSS 7.5v2.16.102006-02-28
CVE-2006-0915 [HIGH] CVE-2006-0915: Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxatta Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.
nvd
Mozilla Bugzilla vulnerabilities | cvebase