Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 2.22 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-0791
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and previous versions versions down to 2.20.1, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.23.3
NA
CVE-2008-7292
Bugzilla 2.20.x prior to 2.20.5, 2.22.x prior to 2.22.3, and 3.0.x prior to 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different vulnerability than C...
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.0.2
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.0.1
NA
CVE-2006-5453
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x prior to 2.18.6, 2.20.x prior to 2.20.3, 2.22.x prior to 2.22.1, and 2.23.x prior to 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3...
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.23.2
NA
CVE-2006-5454
Bugzilla 2.18.x prior to 2.18.6, 2.20.x prior to 2.20.3, 2.22.x prior to 2.22.1, and 2.23.x prior to 2.23.3 allow remote malicious users to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadli...
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.23
NA
CVE-2007-4543
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 up to and including 2.20.4, 2.22.x prior to 2.22.3, and 3.x prior to 3.0.1 allows remote malicious users to inject arbitrary web script or HTML via the buildid field in the "guided form."
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
NA
CVE-2009-0485
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote malicious users to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.22.4
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0.5
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.22
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 3.2
NA
CVE-2008-2103
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote malicious users to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.23
Mozilla Bugzilla 3.0.3
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0 Rc1
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.23.3
Mozilla Bugzilla 2.23.4
NA
CVE-2010-2757
The sudo feature in Bugzilla 2.22rc1 up to and including 3.2.7, 3.3.1 up to and including 3.4.7, 3.5.1 up to and including 3.6.1, and 3.7 up to and including 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to imperson...
Mozilla Bugzilla 2.22.5
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 2.4
Mozilla Bugzilla 3.0.11
Mozilla Bugzilla 3.0.2
Mozilla Bugzilla 3.0.9
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.2
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.8
Mozilla Bugzilla 3.0.3
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.1.0
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.1.3
Mozilla Bugzilla 3.2.6
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.4.4
Mozilla Bugzilla 3.6
NA
CVE-2008-6098
Bugzilla 3.2 prior to 3.2 RC2, 3.0 prior to 3.0.6, 2.22 prior to 2.22.6, 2.20 prior to 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to...
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.9
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.0.7
Mozilla Bugzilla 3.2
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.2.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.20
NA
CVE-2009-0483
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 prior to 2.22.7, 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote malicious users to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cg...
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.16.11
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.18.7
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22.4
Mozilla Bugzilla 2.22
Mozilla Bugzilla 3.0.5
Mozilla Bugzilla 3.0.6
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.16.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-20065
open redirect
CVE-2024-1086
path traversal
CVE-2024-29825
XXE
CVE-2024-29822
CVE-2024-20696
CVE-2024-3564
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »