Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 2.17.7 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-2173
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19.2
NA
CVE-2005-2174
Bugzilla 2.17.x, 2.18 prior to 2.18.2, 2.19.x, and 2.20 prior to 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows malicious users to access information about the bug via buglist.cgi before MySQL replication is compl...
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19.2
NA
CVE-2006-0914
Bugzilla 2.16.10, 2.17 up to and including 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote malicious users to trigger a SQL error.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.16.10
NA
CVE-2004-1061
Cross-site scripting (XSS) vulnerability in Bugzilla prior to 2.18, including 2.16.x prior to 2.16.11, allows remote malicious users to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.16.11
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16.9
Mozilla Bugzilla 2.16.7
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.16.5
Mozilla Bugzilla 2.16.10
NA
CVE-2006-0913
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 up to and including 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.19.2
NA
CVE-2004-1634
show_bug.cgi in Bugzilla 2.17.1 up to and including 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote malicious users to gain sensitive information.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
NA
CVE-2007-4543
Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 up to and including 2.20.4, 2.22.x prior to 2.22.3, and 3.x prior to 3.0.1 allows remote malicious users to inject arbitrary web script or HTML via the buildid field in the "guided form."
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.20.2
NA
CVE-2004-0703
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 up to and including 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.14.1
NA
CVE-2004-0707
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x prior to 2.16.6, and 2.18 prior to 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.14.1
NA
CVE-2004-0702
DBI in Bugzilla 2.17.1 up to and including 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote malicious users to gain sensitive information.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.14.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »