Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 2.4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-4539
The WebService (XML-RPC) interface in Bugzilla 2.23.3 up to and including 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote malicious users to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline...
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 2.23.3
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.9
NA
CVE-2008-4437
Directory traversal vulnerability in importxml.pl in Bugzilla prior to 2.22.5, and 3.x prior to 3.0.5, when --attach_path is enabled, allows remote malicious users to read arbitrary files via an XML file with a .. (dot dot) in the data element.
Mozilla Bugzilla 3.1.3
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.1.2
Mozilla Bugzilla 2.22.3
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 2.23.3
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.6
Mozilla Bugzilla 3.1.4
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.8
Mozilla Bugzilla 3.0.2
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.9
Mozilla Bugzilla 2.22.4
1 EDB exploit
NA
CVE-2003-1042
SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and previous versions allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the product name.
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14
NA
CVE-2003-1044
editproducts.cgi in Bugzilla 2.16.3 and previous versions, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned...
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14
NA
CVE-2003-1045
votes.cgi in Bugzilla 2.16.3 and previous versions, and 2.17.1 up to and including 2.17.4, allows remote malicious users to read a user's voting page when that user has voted on a restricted bug, which allows remote malicious users to read potentially sensitive voting inform...
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14
NA
CVE-2003-1043
SQL injection vulnerability in Bugzilla 2.16.3 and previous versions, and 2.17.1 up to and including 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via the id parameter to editkeywords.cgi.
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14
NA
CVE-2003-1046
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote malicious users to list component descriptions for otherwise restricted products.
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14
NA
CVE-2004-1634
show_bug.cgi in Bugzilla 2.17.1 up to and including 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote malicious users to gain sensitive information.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
NA
CVE-2004-0702
DBI in Bugzilla 2.17.1 up to and including 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote malicious users to gain sensitive information.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.14.1
NA
CVE-2004-0703
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 up to and including 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.8
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.14.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »