Mozilla / Bugzilla
145 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-5123 | A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla… | HIGH | 8.8 | Apr 29, 2019 |
| CVE-2016-2803 | Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject… | MEDIUM | 6.1 | Apr 12, 2017 |
| CVE-2015-8509 | Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files,… | LOW | 3.5 | Jan 3, 2016 |
| CVE-2015-8508 | Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5… | MEDIUM | 4.7 | Jan 3, 2016 |
| CVE-2015-4499 | Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account regist… | HIGH | 7.5 | Sep 14, 2015 |
| CVE-2014-8630 | Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitra… | MEDIUM | 6.5 | Feb 1, 2015 |
| CVE-2014-1573 | Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar con… | MEDIUM | 4.3 | Oct 13, 2014 |
| CVE-2014-1572 | The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.… | MEDIUM | 5.0 | Oct 13, 2014 |
| CVE-2014-1571 | Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users… | MEDIUM | 4.0 | Oct 13, 2014 |
| CVE-2014-1546 | The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10… | MEDIUM | 4.3 | Aug 14, 2014 |
| CVE-2014-1517 | The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt,… | MEDIUM | 4.0 | Apr 20, 2014 |
| CVE-2013-1743 | Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attack… | MEDIUM | 4.3 | Oct 24, 2013 |
| CVE-2013-1742 | Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x… | MEDIUM | 4.3 | Oct 24, 2013 |
| CVE-2013-1734 | Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.… | MEDIUM | 6.8 | Oct 24, 2013 |
| CVE-2013-1733 | Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbit… | MEDIUM | 6.8 | Oct 24, 2013 |
| CVE-2013-0786 | The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for i… | MEDIUM | 5.0 | Feb 24, 2013 |
| CVE-2013-0785 | Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before 4.2.5, and 4.3.x and… | MEDIUM | 4.3 | Feb 24, 2013 |
| CVE-2012-5884 | The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitr… | MEDIUM | 5.0 | Nov 16, 2012 |
| CVE-2012-5883 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.… | MEDIUM | 4.3 | Nov 16, 2012 |
| CVE-2012-4199 | template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x bef… | MEDIUM | 4.3 | Nov 16, 2012 |
| CVE-2012-4198 | The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 ha… | MEDIUM | 4.0 | Nov 16, 2012 |
| CVE-2012-4197 | Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x… | MEDIUM | 5.0 | Nov 16, 2012 |
| CVE-2012-4189 | Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitra… | MEDIUM | 4.3 | Nov 16, 2012 |
| CVE-2012-4747 | Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive informatio… | MEDIUM | 5.0 | Sep 4, 2012 |
| CVE-2012-3981 | Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict… | MEDIUM | 5.0 | Sep 4, 2012 |
Showing 1 to 25 of 145 CVEs