Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 4.0 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-4569
Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote malicious users to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 4.0
NA
CVE-2010-4570
Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote malicious users to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.
Mozilla Bugzilla 4.0
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7.3
NA
CVE-2011-2977
Bugzilla 3.6.x prior to 3.6.6, 3.7.x, 4.0.x prior to 4.0.2, and 4.1.x prior to 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists becau...
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.1
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.6.2
NA
CVE-2012-4198
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x prior to 4.0.9, 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows remote authenticated u...
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.5
Mozilla Bugzilla 4.0.2
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.6
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0.7
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.3
NA
CVE-2012-0440
Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x prior to 3.6.8, 3.7.x and 4.0.x prior to 4.0.4, and 4.1.x and 4.2.x prior to 4.2rc2 allows remote malicious users to hijack the authentication of arbitrary users for requests that use the J...
Mozilla Bugzilla 3.6.7
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.6
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.6.2
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.2
Mozilla Bugzilla 4.0.3
Mozilla Bugzilla 3.5.2
Mozilla Bugzilla 3.5.3
Mozilla Bugzilla 3.5.1
Mozilla Bugzilla 3.5
Mozilla Bugzilla 4.1
NA
CVE-2012-5883
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 up to and including 2.9.0, as used in Bugzilla 3.7.x and 4.0.x prior to 4.0.9, 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1, allows remote malicious users to inject ...
Yahoo Yui 2.8.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.0.4
Mozilla Bugzilla 4.0.5
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 4.3.3
Yahoo Yui 2.8.0
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.7
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.3.1
Yahoo Yui 2.8.2
Yahoo Yui 2.9.0
Mozilla Bugzilla 4.0.2
NA
CVE-2013-0785
Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla prior to 3.6.13, 3.7.x and 4.0.x prior to 4.0.10, 4.1.x and 4.2.x prior to 4.2.5, and 4.3.x and 4.4.x prior to 4.4rc2 allows remote malicious users to inject arbitrary web script or HTML via the id parameter in ...
Mozilla Bugzilla
Mozilla Bugzilla 3.6
Mozilla Bugzilla 3.6.10
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 3.6.9
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.6.11
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.6.2
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.6.8
Mozilla Bugzilla 3.6.7
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.6
Mozilla Bugzilla 4.0.1
NA
CVE-2011-2381
CRLF injection vulnerability in Bugzilla 2.17.1 up to and including 2.22.7, 3.0.x up to and including 3.3.x, 3.4.x prior to 3.4.12, 3.5.x, 3.6.x prior to 3.6.6, 3.7.x, 4.0.x prior to 4.0.2, and 4.1.x prior to 4.1.3 allows remote malicious users to inject arbitrary e-mail headers ...
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22.5
Mozilla Bugzilla 2.22.4
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.18.5
NA
CVE-2013-0786
The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x prior to 3.6.13 and 3.7.x and 4.0.x prior to 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote malicious users to discover private...
Mozilla Bugzilla
Mozilla Bugzilla 3.6
Mozilla Bugzilla 3.6.9
Mozilla Bugzilla 3.6.1
Mozilla Bugzilla 3.6.0
Mozilla Bugzilla 3.6.10
Mozilla Bugzilla 3.6.11
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 3.6.7
Mozilla Bugzilla 3.6.2
Mozilla Bugzilla 3.6.3
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.6.8
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.7.3
Mozilla Bugzilla 3.7
Mozilla Bugzilla 4.0
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.7
Mozilla Bugzilla 4.0.4
NA
CVE-2010-4567
Bugzilla prior to 3.2.10, 3.4.x prior to 3.4.10, 3.6.x prior to 3.6.4, and 4.0.x prior to 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via the URL (aka bu...
Mozilla Bugzilla 3.2.7
Mozilla Bugzilla 3.2
Mozilla Bugzilla 3.4.7
Mozilla Bugzilla 3.4.1
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.16.7
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 3.2.4
Mozilla Bugzilla 3.4.2
Mozilla Bugzilla 3.4.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »