cbcvebase.

Mozilla Bugzilla vulnerabilities

144 known vulnerabilities affecting mozilla/bugzilla.

Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17

Vulnerabilities

Page 5 of 8
CVE-2009-3989P4MEDIUMCVSS 4.3≤ 3.0.10v2.0+75 more2010-02-03
CVE-2009-3989 [MEDIUM] CWE-264 CVE-2009-3989: Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not bloc Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
nvd
CVE-2009-0485P4MEDIUMCVSS 5.8v2.17v2.17.1+43 more2009-02-09
CVE-2009-0485 [MEDIUM] CWE-352 CVE-2009-0485: Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 be Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
nvd
CVE-2002-0807P4HIGHCVSS 7.5v2.14v2.14.1+1 more2002-08-12
CVE-2002-0807 [HIGH] CVE-2002-0807: Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.
nvd
CVE-2010-1204P4MEDIUMCVSS 5.0v2.17.1v2.17.3+42 more2010-06-28
CVE-2010-1204 [MEDIUM] CWE-264 CVE-2010-1204: Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows r Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
nvd
CVE-2002-0803P4MEDIUMCVSS 5.0v2.14v2.14.1+1 more2002-08-12
CVE-2002-0803 [MEDIUM] CVE-2002-0803: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.
nvd
CVE-2003-1045P4MEDIUMCVSS 5.0v2.4v2.6+16 more2004-08-18
CVE-2003-1045 [MEDIUM] CVE-2003-1045: votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.
nvd
CVE-2010-4570P4MEDIUMCVSS 4.3v3.7.1v3.7.2+2 more2011-01-28
CVE-2010-4570 [MEDIUM] CWE-79 CVE-2010-4570: Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.
nvd
CVE-2010-4569P4MEDIUMCVSS 4.3v3.7.1v3.7.2+2 more2011-01-28
CVE-2010-4569 [MEDIUM] CWE-79 CVE-2010-4569: Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote a Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.
nvd
CVE-2010-2758P4MEDIUMCVSS 5.0v2.2v2.4+91 more2010-08-16
CVE-2010-2758 [MEDIUM] CWE-200 CVE-2010-2758: Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 gener Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
nvd
CVE-2005-2173P4MEDIUMCVSS 5.0v2.17.1v2.17.3+10 more2005-07-08
CVE-2005-2173 [MEDIUM] CVE-2005-2173: The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do n The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
nvd
CVE-2012-5883P4MEDIUMCVSS 4.3v3.7v3.7.1+23 more2012-11-16
CVE-2012-5883 [MEDIUM] CVE-2012-5883: Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore.swf, a similar issue to CVE-2010-4209.
nvd
CVE-2010-4567P4MEDIUMCVSS 4.3≤ 3.2.9v2.0+96 more2011-01-28
CVE-2010-4567 [MEDIUM] CWE-79 CVE-2010-4567: Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not pr Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the URL (aka bug_file_loc) field.
nvd
CVE-2011-3657P4MEDIUMCVSS 4.3v2.0v2.2+142 more2012-01-02
CVE-2011-3657 [MEDIUM] CWE-79 CVE-2011-3657: Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) tabular report, (2) graphical report, or (3) new chart.
nvd
CVE-2008-6098P4MEDIUMCVSS 4.0v2.17.4v2.17.5+56 more2009-02-09
CVE-2008-6098 [MEDIUM] CWE-264 CVE-2008-6098: Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other ver Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to "approve."
nvd
CVE-2004-1634P4MEDIUMCVSS 5.0v2.4v2.6+23 more2004-10-25
CVE-2004-1634 [MEDIUM] CVE-2004-1634: show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup featu show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.
nvd
CVE-2002-0009P4MEDIUMCVSS 5.0≤ 2.14.12002-01-31
CVE-2002-0009 [MEDIUM] CVE-2002-0009: show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other prod show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.
nvd
CVE-2004-1633P4MEDIUMCVSS 5.0v2.9v2.10+22 more2004-10-25
CVE-2004-1633 [MEDIUM] CVE-2004-1633: process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.
nvd
CVE-2005-3139P4MEDIUMCVSS 5.0v2.19.1v2.19.2+3 more2005-10-05
CVE-2005-3139 [MEDIUM] CVE-2005-3139: Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows att Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.
nvd
CVE-2011-0048P4MEDIUMCVSS 4.3≤ 3.2.9v2.0+96 more2011-01-28
CVE-2011-0048 [MEDIUM] CWE-79 CVE-2011-0048: Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a c Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scripting (XSS) attacks against logged-out users via a crafted URI.
nvd
CVE-2011-2379P4MEDIUMCVSS 4.3v2.4v2.6+113 more2011-08-09
CVE-2011-2379 [MEDIUM] CWE-79 CVE-2011-2379: Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9 or Safari before 5.0.6 is used for Raw Unified mode, allows remote attackers to inject arbitrary web script or HTML via a crafted
nvd