cbcvebase.

Mozilla Bugzilla vulnerabilities

144 known vulnerabilities affecting mozilla/bugzilla.

Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17

Vulnerabilities

Page 7 of 8
CVE-2004-1061P4MEDIUMCVSS 4.3v2.16.1v2.16.2+16 more2005-01-04
CVE-2004-1061 [MEDIUM] CVE-2004-1061: Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, a Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
nvd
CVE-2012-0448P4MEDIUMCVSS 4.0v2.0v2.2+145 more2012-02-02
CVE-2012-0448 [MEDIUM] CWE-20 CVE-2012-0448: Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.
nvd
CVE-2002-0011P4MEDIUMCVSS 5.0≤ 2.14.12002-01-31
CVE-2002-0011 [MEDIUM] CVE-2002-0011: Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more eas Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.
nvd
CVE-2005-3138P4MEDIUMCVSS 5.0v2.18v2.18.1+8 more2005-10-05
CVE-2005-3138 [MEDIUM] CVE-2005-3138: Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain se Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
nvd
CVE-2006-2420P4MEDIUMCVSS 4.3v2.20v2.21+1 more2006-05-16
CVE-2006-2420 [MEDIUM] CWE-79 CVE-2006-2420: Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cro Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within
nvd
CVE-2002-2260P4MEDIUMCVSS 4.3v2.10v2.12+25 more2002-12-31
CVE-2002-2260 [MEDIUM] CWE-79 CVE-2002-2260: Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.
nvd
CVE-2012-0466P4MEDIUMCVSS 4.0v2.0v2.2+146 more2012-04-27
CVE-2012-0466 [MEDIUM] CWE-264 CVE-2012-0466: template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4 template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page.
nvd
CVE-2010-3172P4LOWCVSS 2.6≤ 3.2.8v2.0+93 more2010-11-05
CVE-2010-3172 [LOW] CWE-94 CVE-2010-3172: CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4 CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.
nvd
CVE-2006-5455P4LOWCVSS 2.6≤ 2.22.1v2.23+2 more2006-10-23
CVE-2006-5455 [LOW] CVE-2006-5455: Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2. Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
nvd
CVE-2006-5453P4LOWCVSS 3.5v2.18v2.18.1+11 more2006-10-23
CVE-2006-5453 [LOW] CVE-2006-5453: Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3 HTML tags in global/header.html.tmpl, (2) description fields of certain items in various edi
nvd
CVE-2008-2105P4LOWCVSS 3.5v2.4v2.6+64 more2008-05-07
CVE-2008-2105 [LOW] CWE-264 CVE-2008-2105: email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticat email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses
nvd
CVE-2003-0603P4LOWCVSS 2.1v2.10v2.12+12 more2003-08-27
CVE-2003-0603 [LOW] CVE-2003-0603: Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to over Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.
nvd
CVE-2009-0481P4LOWCVSS 3.5v2.10v2.12+67 more2009-02-09
CVE-2009-0481 [LOW] CWE-79 CVE-2009-0481: Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote a Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.
nvd
CVE-2005-2174P4LOWCVSS 2.6v2.17.1v2.17.3+10 more2005-07-08
CVE-2005-2174 [LOW] CVE-2005-2174: Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
nvd
CVE-2002-0805P4MEDIUMCVSS 4.6v2.14v2.14.1+1 more2002-08-12
CVE-2002-0805 [MEDIUM] CVE-2002-0805: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writabl Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.
nvd
CVE-2001-1405P4LOWCVSS 2.1v2.4v2.6+4 more2001-09-10
CVE-2001-1405 [LOW] CVE-2001-1405: Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
nvd
CVE-2004-0706P4LOWCVSS 2.1v2.4v2.6+22 more2004-07-27
CVE-2004-0706 [LOW] CVE-2004-0706: Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.
nvd
CVE-2003-0012P4LOWCVSS 2.1v2.14v2.14.1+7 more2003-01-17
CVE-2003-0012 [LOW] CVE-2003-0012: The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x befor The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.
nvd
CVE-2002-0806P4LOWCVSS 2.1v2.14v2.14.1+1 more2002-08-12
CVE-2002-0806 [LOW] CVE-2002-0806: Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privil Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
nvd
CVE-2001-1406P4LOWCVSS 2.1v2.4v2.6+4 more2001-09-10
CVE-2001-1406 [LOW] CVE-2001-1406: process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent.
nvd