cbcvebase.

Mozilla Bugzilla vulnerabilities

144 known vulnerabilities affecting mozilla/bugzilla.

Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17

Vulnerabilities

Page 4 of 8
CVE-2013-0786P4MEDIUMCVSS 5.0≤ 3.6.12v3.6+99 more2013-02-24
CVE-2013-0786 [MEDIUM] CWE-200 CVE-2013-0786: The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4 The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.
nvd
CVE-2009-3166P4MEDIUMCVSS 5.0v3.4v3.4.12009-09-15
CVE-2009-3166 [MEDIUM] CWE-255 CVE-2009-3166: token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login se token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
nvd
CVE-2006-0914P4MEDIUMCVSS 5.5v2.16.10v2.17+10 more2006-02-28
CVE-2006-0914 [MEDIUM] CWE-20 CVE-2006-0914: Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the m Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.
nvd
CVE-2001-1402P4HIGHCVSS 7.5v2.4v2.6+4 more2001-09-10
CVE-2001-1402 [HIGH] CVE-2001-1402: Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attacke Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in crea
nvd
CVE-2011-2979P4MEDIUMCVSS 5.0v4.1v4.1.1+1 more2011-08-09
CVE-2011-2979 [MEDIUM] CVE-2011-2979: Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search. NOTE: this vulnerability exists because of a CVE-2010-2756 regression.
nvd
CVE-2001-1403P4HIGHCVSS 7.5v2.4v2.6+4 more2001-09-10
CVE-2001-1403 [HIGH] CVE-2001-1403: Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.
nvd
CVE-2002-0809P4HIGHCVSS 7.5v2.14v2.14.1+1 more2002-08-12
CVE-2002-0809 [HIGH] CVE-2002-0809: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field nam Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.
nvd
CVE-2012-0453P4MEDIUMCVSS 5.1v4.0.2v4.0.3+5 more2012-02-25
CVE-2012-0453 [MEDIUM] CWE-352 CVE-2012-0453: Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4. Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.
nvd
CVE-2012-0440P4MEDIUMCVSS 5.1v3.6v3.6.0+24 more2012-02-02
CVE-2012-0440 [MEDIUM] CWE-352 CVE-2012-0440: Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3. Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of arbitrary users for requests that use the JSON-RPC API.
nvd
CVE-2015-8508P4MEDIUMCVSS 4.7v2.0v2.2+145 more2016-01-03
CVE-2015-8508 [MEDIUM] CWE-79 CVE-2015-8508: Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x be Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2, when a local dot configuration is used, allows remote attackers to inject arbitrary web script or HTML via a crafted bug summary.
nvd
CVE-2002-1196P4HIGHCVSS 7.5v2.14v2.14.1+3 more2002-10-28
CVE-2002-1196 [HIGH] CVE-2002-1196: editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
nvd
CVE-2009-3387P4MEDIUMCVSS 5.0v3.3.1v3.3.2+8 more2010-02-03
CVE-2009-3387 [MEDIUM] CWE-264 CVE-2009-3387: Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved thr Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
nvd
CVE-2007-4539P4MEDIUMCVSS 5.0v2.4v2.6+5 more2007-08-27
CVE-2007-4539 [MEDIUM] CWE-264 CVE-2007-4539: The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
nvd
CVE-2014-1573P4MEDIUMCVSS 4.3v2.0v2.2+182 more2014-10-13
CVE-2014-1573 [MEDIUM] CWE-79 CVE-2014-1573: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4. Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
nvd
CVE-2009-0483P4MEDIUMCVSS 5.8v2.10v2.12+67 more2009-02-09
CVE-2009-0483 [MEDIUM] CWE-352 CVE-2009-0483: Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3. Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.
nvd
CVE-2009-0484P4MEDIUMCVSS 5.8v3.0.0v3.0.1+7 more2009-02-09
CVE-2009-0484 [MEDIUM] CWE-352 CVE-2009-0484: Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete shared or saved searches via a link or IMG tag to buglist.cgi.
nvd
CVE-2009-0482P4MEDIUMCVSS 5.8v2.10v2.12+67 more2009-02-09
CVE-2009-0482 [MEDIUM] CWE-352 CVE-2009-0482: Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3. Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.
nvd
CVE-2010-3764P4MEDIUMCVSS 5.0v2.2v2.4+82 more2010-11-05
CVE-2010-3764 [MEDIUM] CWE-200 CVE-2010-3764: The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates g The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
nvd
CVE-2002-0808P4HIGHCVSS 7.5v2.14v2.14.1+1 more2002-08-12
CVE-2002-0808 [HIGH] CVE-2002-0808: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groups Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.
nvd
CVE-2012-5884P4MEDIUMCVSS 5.0v4.3.22012-11-16
CVE-2012-5884 [MEDIUM] CVE-2012-5884: The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obta The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-2012-4198.
nvd