Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 4.1.1 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2011-2979
Bugzilla 4.1.x prior to 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote malicious users to determine the existence of private group names via a custom search. NOTE: this vulnerability exists becaus...
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.1
5.1
CVSSv2
CVE-2012-0453
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 up to and including 4.0.4 and 4.1.1 up to and including 4.2rc2, when mod_perl is used, allows remote malicious users to hijack the authentication of arbitrary users for requests that modify the produc...
Mozilla Bugzilla 4.0.2
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.1.3
4.3
CVSSv2
CVE-2012-1968
Bugzilla 4.1.x and 4.2.x prior to 4.2.2 and 4.3.x prior to 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote malicious users to obtain sensitive description information by reading the toolti...
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.3.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.3
4.3
CVSSv2
CVE-2012-4189
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1, allows remote malicious users to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, a...
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.3.1
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 4.3.3
2.1
CVSSv2
CVE-2011-2977
Bugzilla 3.6.x prior to 3.6.6, 3.7.x, 4.0.x prior to 4.0.2, and 4.1.x prior to 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists becau...
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.1
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.6.2
4.3
CVSSv2
CVE-2013-1743
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x prior to 4.2.7 and 4.3.x and 4.4.x prior to 4.4.1 allow remote malicious users to inject arbitrary web script or HTML via a field value that is not properly handled during construction o...
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.3.1
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 4.3.3
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.2.4
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.5
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.4
1 EDB exploit
4
CVSSv2
CVE-2012-4198
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x prior to 4.0.9, 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated u...
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.5
Mozilla Bugzilla 4.0.2
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.6
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0.7
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.3
4.3
CVSSv2
CVE-2012-0465
Bugzilla 3.5.x and 3.6.x prior to 3.6.9, 3.7.x and 4.0.x prior to 4.0.6, and 4.1.x and 4.2.x prior to 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote malicious users to bypass the lockout policy vi...
Mozilla Bugzilla 3.5.3
Mozilla Bugzilla 3.5.2
Mozilla Bugzilla 3.5.1
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 4.0.5
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 3.6.2
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 3.6.7
Mozilla Bugzilla 3.6.8
Mozilla Bugzilla 4.0.2
5.1
CVSSv2
CVE-2012-0440
Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x prior to 3.6.8, 3.7.x and 4.0.x prior to 4.0.4, and 4.1.x and 4.2.x prior to 4.2rc2 allows remote malicious users to hijack the authentication of arbitrary users for requests that use the J...
Mozilla Bugzilla 3.6.7
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.6
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.6.2
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.2
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 3.5.2
Mozilla Bugzilla 3.5.3
Mozilla Bugzilla 3.5.1
Mozilla Bugzilla 3.5
Mozilla Bugzilla 4.1
4.3
CVSSv2
CVE-2012-5883
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 up to and including 2.9.0, as used in Bugzilla 3.7.x and 4.0.x prior to 4.0.9, 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1, allows remote malicious users to inject ...
Yahoo Yui 2.8.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.5
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 4.3.3
Yahoo Yui 2.8.0
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.7
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.3.1
Yahoo Yui 2.8.2
Yahoo Yui 2.9.0
Mozilla Bugzilla 4.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »