Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 2.18.1 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2005-3138
Bugzilla 2.18rc1 up to and including 2.18.3, 2.19 up to and including 2.20rc2, and 2.21 allows remote malicious users to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.1
5
CVSSv2
CVE-2005-2173
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19.1
5.5
CVSSv2
CVE-2006-0914
Bugzilla 2.16.10, 2.17 up to and including 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote malicious users to trigger a SQL error.
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.16.10
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
2.6
CVSSv2
CVE-2005-2174
Bugzilla 2.17.x, 2.18 prior to 2.18.2, 2.19.x, and 2.20 prior to 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows malicious users to access information about the bug via buglist.cgi before MySQL replication is compl...
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.19.3
3.5
CVSSv2
CVE-2006-5453
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x prior to 2.18.6, 2.20.x prior to 2.20.3, 2.22.x prior to 2.22.1, and 2.23.x prior to 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3...
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.23.2
5
CVSSv2
CVE-2006-5454
Bugzilla 2.18.x prior to 2.18.6, 2.20.x prior to 2.20.3, 2.22.x prior to 2.22.1, and 2.23.x prior to 2.23.3 allow remote malicious users to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadli...
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.23
5.5
CVSSv2
CVE-2006-0913
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 up to and including 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.4
5
CVSSv2
CVE-2005-1563
Bugzilla 2.10 up to and including 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote malicious users to determine hidden products.
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.16.7
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.14
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.10
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 2.16.9
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.16.5
Mozilla Bugzilla 2.19.1
4.3
CVSSv2
CVE-2007-4543
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 up to and including 2.20.4, 2.22.x prior to 2.22.3, and 3.x prior to 3.0.1 allows remote malicious users to inject arbitrary web script or HTML via the buildid field in the "guided form."
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
5.8
CVSSv2
CVE-2009-0485
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote malicious users to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.22.4
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0.5
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.22
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 3.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3661
open redirect
CVE-2024-25512
CVE-2024-33788
command injection
SSTI
CVE-2024-0043
CVE-2024-29210
CVE-2024-25510
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »