Mozilla Bugzilla vulnerabilities
144 known vulnerabilities affecting mozilla/bugzilla.
Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17
Vulnerabilities
Page 6 of 8
CVE-2012-1969P4MEDIUMCVSS 4.3v2.0v2.2+153 more2012-07-30
CVE-2012-1969 [MEDIUM] CWE-264 CVE-2012-1969: The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0
The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description inf
nvd
CVE-2011-2976P4MEDIUMCVSS 4.3v2.16v2.16.1+93 more2011-08-09
CVE-2011-2976 [MEDIUM] CWE-79 CVE-2011-2976: Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, an
Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving a BUGLIST cookie.
nvd
CVE-2013-0785P4MEDIUMCVSS 4.3≤ 3.6.12v3.6+40 more2013-02-24
CVE-2013-0785 [MEDIUM] CWE-79 CVE-2013-0785: Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x
Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before 4.2.5, and 4.3.x and 4.4.x before 4.4rc2 allows remote attackers to inject arbitrary web script or HTML via the id parameter in conjunction with an invalid value of the format parameter.
nvd
CVE-2003-0602P4MEDIUMCVSS 6.8v2.16v2.16.1+4 more2003-08-27
CVE-2003-0602 [MEDIUM] CVE-2003-0602: Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x befo
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.
nvd
CVE-2010-2759P4MEDIUMCVSS 4.0v2.4v2.6+49 more2010-08-16
CVE-2010-2759 [MEDIUM] CWE-189 CVE-2010-2759: Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when
Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases, which allows remote authenticated users to cause a denial of service (bug invisibility) via a crafted comment.
nvd
CVE-2014-1571P4MEDIUMCVSS 4.0v2.0v2.2+182 more2014-10-13
CVE-2014-1571 [MEDIUM] CWE-200 CVE-2014-1571: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.
nvd
CVE-2005-1565P4MEDIUMCVSS 5.0v2.10v2.12+22 more2005-05-12
CVE-2005-1565 [MEDIUM] CVE-2005-1565: Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting
Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.
nvd
CVE-2004-0702P4MEDIUMCVSS 5.0v2.4v2.6+22 more2004-07-27
CVE-2004-0702 [MEDIUM] CVE-2004-0702: DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQ
DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.
nvd
CVE-2012-1968P4MEDIUMCVSS 4.3v4.1v4.1.1+6 more2012-07-30
CVE-2012-1968 [MEDIUM] CWE-264 CVE-2012-1968: Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of b
Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information by reading the tooltip portions of an HTML e-mail message.
nvd
CVE-2007-4543P4MEDIUMCVSS 4.3v2.17.1v2.17.3+22 more2007-08-27
CVE-2007-4543 [MEDIUM] CWE-79 CVE-2007-4543: Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form."
nvd
CVE-2012-4199P4MEDIUMCVSS 4.3≤ 3.6.11v3.0+88 more2012-11-16
CVE-2012-4199 [MEDIUM] CWE-200 CVE-2012-4199: template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4
template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates JavaScript function calls containing private product names or private component names in certain circumstances involving custom-field visibility control, which allows remote
nvd
CVE-2014-1517P4MEDIUMCVSS 4.0v2.0v2.2+180 more2014-04-20
CVE-2014-1517 [MEDIUM] CWE-287 CVE-2014-1517: The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly hand
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related
nvd
CVE-2015-8509P4LOWCVSS 3.5v2.0v2.2+145 more2016-01-03
CVE-2015-8509 [LOW] CWE-200 CVE-2015-8509: Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x an
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.
nvd
CVE-2005-1563P4MEDIUMCVSS 5.0v2.10v2.12+21 more2005-05-14
CVE-2005-1563 [MEDIUM] CVE-2005-1563: Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on wheth
Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.
nvd
CVE-2008-2103P4MEDIUMCVSS 4.3v2.17.2v2.17.3+42 more2008-05-07
CVE-2008-2103 [MEDIUM] CWE-79 CVE-2008-2103: Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inj
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
nvd
CVE-2007-0791P4MEDIUMCVSS 4.3v2.20.1v2.20.2+8 more2007-02-06
CVE-2007-0791 [MEDIUM] CVE-2007-0791: Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and e
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-1546P4MEDIUMCVSS 4.3v3.0v3.0.0+111 more2014-08-14
CVE-2014-1546 [MEDIUM] CWE-352 CVE-2014-1546: The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzil
The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct
nvd
CVE-2008-2104P4MEDIUMCVSS 4.0v3.1.32008-05-07
CVE-2008-2104 [MEDIUM] CWE-264 CVE-2008-2104: The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to
The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.
nvd
CVE-2012-4198P4MEDIUMCVSS 4.0v3.7v3.7.1+23 more2012-11-16
CVE-2012-4198 [MEDIUM] CWE-200 CVE-2012-4198: The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x a
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated users to discover private group names by observing whether a call throws an erro
nvd
CVE-2002-0810P4MEDIUMCVSS 5.0v2.14v2.14.1+1 more2002-08-12
CVE-2002-0810 [MEDIUM] CVE-2002-0810: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb c
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.
nvd