Mozilla Bugzilla vulnerabilities

144 known vulnerabilities affecting mozilla/bugzilla.

Total CVEs
144
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17

Vulnerabilities

Page 8 of 8
CVE-2001-1405LOWCVSS 2.1v2.4v2.6+4 more2001-09-10
CVE-2001-1405 [LOW] CVE-2001-1405: Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
nvd
CVE-2001-0330HIGHCVSS 7.5v2.4v2.6+2 more2001-06-27
CVE-2001-0330 [HIGH] CVE-2001-0330: Bugzilla 2.10 allows remote attackers to access sensitive information, including the database userna Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.
nvd
CVE-2001-0329HIGHCVSS 7.5PoCv2.4v2.6+2 more2001-06-27
CVE-2001-0329 [HIGH] CVE-2001-0329: Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a us Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.
nvd
CVE-2000-0421HIGHCVSS 7.5v2.82000-05-11
CVE-2000-0421 [HIGH] CVE-2000-0421: The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via she The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.
nvd