Mozilla Bugzilla vulnerabilities
144 known vulnerabilities affecting mozilla/bugzilla.
Total CVEs
144
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH36MEDIUM88LOW17
Vulnerabilities
Page 8 of 8
CVE-2010-0180P4LOWCVSS 1.9v3.5.1v3.5.2+3 more2010-06-28
CVE-2010-0180 [LOW] CWE-264 CVE-2010-0180: Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.
nvd
CVE-2008-7292P4LOWCVSS 2.1v2.20v2.20.1+10 more2011-08-09
CVE-2008-7292 [LOW] CWE-200 CVE-2008-7292: Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not dele
Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2011-2977.
nvd
CVE-2011-2977P4LOWCVSS 2.1v3.6.0v3.6.1+13 more2011-08-09
CVE-2011-2977 [LOW] CVE-2011-2977: Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not d
Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists because of a regression in 3.6.
nvd
CVE-2010-2470P4LOWCVSS 1.9v3.5.1v3.5.2+5 more2010-06-28
CVE-2010-2470 [LOW] CVE-2010-2470: Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enab
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.
nvd
← Previous8 / 8