Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 3.0.0 vulnerabilities and exploits
(subscribe to this query)
5.8
CVSSv2
CVE-2009-0484
Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote malicious users to delete shared or saved searches via a link or IMG tag to buglist.cgi.
Mozilla Bugzilla 3.0.2
Mozilla Bugzilla 3.0.3
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 3.3.1
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0.5
Mozilla Bugzilla 3.0.6
Mozilla Bugzilla 3.2
5
CVSSv2
CVE-2014-1572
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x up to and including 4.0.x prior to 4.0.15, 4.1.x and 4.2.x prior to 4.2.11, 4.3.x and 4.4.x prior to 4.4.6, and 4.5.x prior to 4.5.6 does not specify a scalar context for the realname...
Fedoraproject Fedora 20
Fedoraproject Fedora 19
Fedoraproject Fedora 21
Mozilla Bugzilla 4.5.5
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.4.2
Mozilla Bugzilla 4.4.3
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.2.10
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.5.3
Mozilla Bugzilla 4.5.4
Mozilla Bugzilla 4.4
Mozilla Bugzilla 4.4.1
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.8
Mozilla Bugzilla 4.2.9
Mozilla Bugzilla 4.0.12
Mozilla Bugzilla 4.0.11
5
CVSSv2
CVE-2012-4197
Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x prior to 3.6.12, 3.7.x and 4.0.x prior to 4.0.9, 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1 allows remote malicious users to read attachment descriptions from private bugs via an obsolete=1 ...
Mozilla Bugzilla 2.18.6\\+
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.1
5
CVSSv2
CVE-2012-3981
Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x prior to 3.6.11, 3.7.x and 4.0.x prior to 4.0.8, 4.1.x and 4.2.x prior to 4.2.3, and 4.3.x prior to 4.3.3 does not restrict the characters in a username, which might allow remote malicious users to inject data into an LDAP directory via...
Mozilla Bugzilla 2.18.6\\+
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.16.5
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20.6
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.0
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20.2
5
CVSSv2
CVE-2012-4747
Bugzilla 2.x and 3.x up to and including 3.6.11, 3.7.x and 4.0.x prior to 4.0.8, 4.1.x and 4.2.x prior to 4.2.3, and 4.3.x prior to 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote malicious users to read (1) ...
Mozilla Bugzilla 2.18.6\\+
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.16.7
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 2.16.9
Mozilla Bugzilla 2.18.9
Mozilla Bugzilla 2.18.4
5
CVSSv2
CVE-2011-2380
Bugzilla 2.23.3 up to and including 2.22.7, 3.0.x up to and including 3.3.x, 3.4.x prior to 3.4.12, 3.5.x, 3.6.x prior to 3.6.6, 3.7.x, 4.0.x prior to 4.0.2, and 4.1.x prior to 4.1.3 allows remote malicious users to determine the existence of private group names via a crafted par...
Mozilla Bugzilla 2.23.3
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 2.23
Mozilla Bugzilla 3.4
Mozilla Bugzilla 3.4.1
Mozilla Bugzilla 3.4.2
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.4.11
Mozilla Bugzilla 3.4.8
Mozilla Bugzilla 3.4.10
Mozilla Bugzilla 3.4.7
Mozilla Bugzilla 3.4.9
Mozilla Bugzilla 3.4.4
Mozilla Bugzilla 3.4.6
Mozilla Bugzilla 3.4.5
Mozilla Bugzilla 3.5.2
Mozilla Bugzilla 3.5.3
Mozilla Bugzilla 3.5.1
Mozilla Bugzilla 3.5
Mozilla Bugzilla 3.6.2
5
CVSSv2
CVE-2011-2978
Bugzilla 2.16rc1 up to and including 2.22.7, 3.0.x up to and including 3.3.x, 3.4.x prior to 3.4.12, 3.5.x, 3.6.x prior to 3.6.6, 3.7.x, 4.0.x prior to 4.0.2, and 4.1.x prior to 4.1.3 does not prevent changes to the confirmation e-mail address (aka old_email field) for e-mail cha...
Mozilla Bugzilla 2.16.11
Mozilla Bugzilla 2.16.10
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.16.7
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 2.16.9
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22.4
5
CVSSv2
CVE-2010-2756
Search.pm in Bugzilla 2.19.1 up to and including 3.2.7, 3.3.1 up to and including 3.4.7, 3.5.1 up to and including 3.6.1, and 3.7 up to and including 3.7.2 allows remote malicious users to determine the group memberships of arbitrary users via vectors involving the Search interfa...
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.9
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0.5
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.2.5
Mozilla Bugzilla 3.2.4
Mozilla Bugzilla 3.2.7
Mozilla Bugzilla 3.3.1
Mozilla Bugzilla 3.4.4
Mozilla Bugzilla 3.4.5
Mozilla Bugzilla 3.7
Mozilla Bugzilla 3.7.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.21
5
CVSSv2
CVE-2010-2758
Bugzilla 2.17.1 up to and including 3.2.7, 3.3.1 up to and including 3.4.7, 3.5.1 up to and including 3.6.1, and 3.7 up to and including 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote malicious users to guess produ...
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.2
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.9
Mozilla Bugzilla 3.0.3
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.1.0
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.2.6
Mozilla Bugzilla 3.2.7
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.4.4
Mozilla Bugzilla 3.6
5
CVSSv2
CVE-2007-4539
The WebService (XML-RPC) interface in Bugzilla 2.23.3 up to and including 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote malicious users to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline...
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.9
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.23.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »