Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 2.21 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-2420
Bugzilla 2.20rc1 up to and including 2.20 and 2.21.1, when using RSS 1.0, allows remote malicious users to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers....
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21
NA
CVE-2005-3139
Bugzilla 2.19.1 up to and including 2.20rc2 and 2.21, with user matching turned on in substring mode, allows malicious users to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.19.2
NA
CVE-2006-0916
Bugzilla 2.19.3 up to and including 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another dom...
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21
NA
CVE-2005-3138
Bugzilla 2.18rc1 up to and including 2.18.3, 2.19 up to and including 2.20rc2, and 2.21 allows remote malicious users to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.19.2
NA
CVE-2007-0791
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and previous versions versions down to 2.20.1, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.23.3
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21
NA
CVE-2006-0913
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 up to and including 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.19.2
NA
CVE-2009-0485
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote malicious users to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0
Mozilla Bugzilla 2.18.6+
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 3.2
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 3.0.6
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.22.2
NA
CVE-2008-6098
Bugzilla 3.2 prior to 3.2 RC2, 3.0 prior to 3.0.6, 2.22 prior to 2.22.6, 2.20 prior to 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to...
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.1.3
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.3.2
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.1.2
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.21.2
NA
CVE-2009-0483
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 prior to 2.22.7, 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote malicious users to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cg...
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.16 Rc2
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.16.11
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 2.17.4
NA
CVE-2009-0482
Cross-site request forgery (CSRF) vulnerability in Bugzilla prior to 3.2 prior to 3.2.1, 3.3 prior to 3.3.2, and other versions prior to 3.2 allows remote malicious users to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.16 Rc2
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.16.11
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 2.17.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »