Mozilla Bugzilla vulnerabilities
144 known vulnerabilities affecting mozilla/bugzilla.
Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17
Vulnerabilities
Page 2 of 8
CVE-2011-3667P4MEDIUMCVSS 6.8v2.0v2.2+142 more2012-01-02
CVE-2011-3667 [MEDIUM] CWE-287 CVE-2011-3667: The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3
The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contain
nvd
CVE-2000-0421P4HIGHCVSS 7.5v2.82000-05-11
CVE-2000-0421 [HIGH] CVE-2000-0421: The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via she
The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.
nvd
CVE-2002-1198P4HIGHCVSS 7.5v2.14v2.14.1+4 more2002-10-28
CVE-2002-1198 [HIGH] CVE-2002-1198: Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during acco
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.
nvd
CVE-2009-0486P4HIGHCVSS 7.5v3.0.7v3.2.1+1 more2009-02-09
CVE-2009-0486 [HIGH] CWE-352 CVE-2009-0486: Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup t
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as oth
nvd
CVE-2014-1572P4MEDIUMCVSS 5.0v2.0v2.2+182 more2014-10-13
CVE-2014-1572 [MEDIUM] CWE-264 CVE-2014-1572: The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x thr
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses
nvd
CVE-2002-1197P4HIGHCVSS 7.5v2.14v2.14.1+3 more2002-10-28
CVE-2002-1197 [HIGH] CVE-2002-1197: bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote a
bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.
nvd
CVE-2003-1046P4HIGHCVSS 7.5v2.4v2.6+16 more2004-08-18
CVE-2003-1046 [HIGH] CVE-2003-1046: describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
nvd
CVE-2003-0013P4HIGHCVSS 7.5v2.14v2.14.1+7 more2003-01-17
CVE-2003-0013 [HIGH] CVE-2003-0013: The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x be
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.
nvd
CVE-2010-2756P4MEDIUMCVSS 5.0v2.2v2.4+72 more2010-08-16
CVE-2010-2756 [MEDIUM] CWE-264 CVE-2010-2756: Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 throug
Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and group-based pronouns.
nvd
CVE-2012-4197P4MEDIUMCVSS 5.0v2.0v2.2+161 more2012-11-16
CVE-2012-4197 [MEDIUM] CWE-200 CVE-2012-4197: Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x befo
Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allows remote attackers to read attachment descriptions from private bugs via an obsolete=1 insert action.
nvd
CVE-2011-0046P4MEDIUMCVSS 6.8≤ 3.2.9v2.0+96 more2011-01-28
CVE-2011-0046 [MEDIUM] CWE-352 CVE-2011-0046: Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3
Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi,
nvd
CVE-2011-3669P4MEDIUMCVSS 6.8v2.0v2.2+143 more2012-01-02
CVE-2011-3669 [MEDIUM] CWE-352 CVE-2011-3669: Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x befo
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that upload attachments.
nvd
CVE-2011-3668P4MEDIUMCVSS 6.8v2.0v2.2+143 more2012-01-02
CVE-2011-3668 [MEDIUM] CWE-352 CVE-2011-3668: Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before
Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that create bug reports.
nvd
CVE-2013-1733P4MEDIUMCVSS 6.8v4.42013-10-24
CVE-2013-1733 [MEDIUM] CWE-352 CVE-2013-1733: Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 al
Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs via vectors involving a midair-collision token.
nvd
CVE-2013-1734P4MEDIUMCVSS 6.8v2.0v2.2+168 more2013-10-24
CVE-2013-1734 [MEDIUM] CWE-352 CVE-2013-1734: Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x be
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action.
nvd
CVE-2010-2757P4MEDIUMCVSS 6.5v2.4v2.6+57 more2010-08-16
CVE-2010-2757 [MEDIUM] CWE-310 CVE-2010-2757: The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users without discovery.
nvd
CVE-2001-0330P4HIGHCVSS 7.5v2.4v2.6+2 more2001-06-27
CVE-2001-0330 [HIGH] CVE-2001-0330: Bugzilla 2.10 allows remote attackers to access sensitive information, including the database userna
Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.
nvd
CVE-2005-1564P4HIGHCVSS 7.5v2.10v2.12+22 more2005-05-12
CVE-2005-1564 [HIGH] CVE-2005-1564: post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
nvd
CVE-2012-4747P4MEDIUMCVSS 5.0v2.0v2.2+157 more2012-09-04
CVE-2012-4747 [MEDIUM] CWE-264 CVE-2012-4747: Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to read (1) template (aka .tmpl) files, (2) other custom extension files under extensions/, or (3) custom doc
nvd
CVE-2002-0804P4HIGHCVSS 7.5v2.14v2.14.1+1 more2002-08-12
CVE-2002-0804 [HIGH] CVE-2002-0804: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.
nvd