Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mozilla bugzilla 2.20 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2006-2420
Bugzilla 2.20rc1 up to and including 2.20 and 2.21.1, when using RSS 1.0, allows remote malicious users to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers....
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.21.1
4
CVSSv2
CVE-2014-1571
Bugzilla 2.x up to and including 4.0.x prior to 4.0.15, 4.1.x and 4.2.x prior to 4.2.11, 4.3.x and 4.4.x prior to 4.4.6, and 4.5.x prior to 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to...
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.3.1
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 4.3.3
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.2.4
Mozilla Bugzilla 4.2.5
Mozilla Bugzilla 4.2.6
Mozilla Bugzilla 4.0.10
Mozilla Bugzilla 4.0.1
Mozilla Bugzilla 4.0
Mozilla Bugzilla 3.6.13
Mozilla Bugzilla 3.6.12
Mozilla Bugzilla 3.6.11
Mozilla Bugzilla 3.6.10
Mozilla Bugzilla 3.4.4
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.4.2
Mozilla Bugzilla 3.4.13
Mozilla Bugzilla 3.2.8
Mozilla Bugzilla 3.2.7
4
CVSSv2
CVE-2014-1517
The login form in Bugzilla 2.x, 3.x, 4.x prior to 4.4.3, and 4.5.x prior to 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to log...
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.6.9
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 3.1.3
Mozilla Bugzilla 2.0
Mozilla Bugzilla 2.18.6\\+
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 4.3.1
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 3.7.2
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.3.2
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.16
Mozilla Bugzilla 4.2
Mozilla Bugzilla 3.2
Mozilla Bugzilla 2.18.5
4
CVSSv2
CVE-2012-0466
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x prior to 3.6.9, 3.7.x and 4.0.x prior to 4.0.6, and 4.1.x and 4.2.x prior to 4.2.1 does not properly handle multiple logins, which allows remote malicious users to conduct cross-site scripting (XSS) attacks and obtain ...
Mozilla Bugzilla 2.22.7
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.23.3
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.16.7
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.22.4
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.18.9
Mozilla Bugzilla 2.16.9
Mozilla Bugzilla 2.18.6\\+
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20.1
4
CVSSv2
CVE-2012-0448
Bugzilla 2.x and 3.x prior to 3.4.14, 3.5.x and 3.6.x prior to 3.6.8, 3.7.x and 4.0.x prior to 4.0.4, and 4.1.x and 4.2.x prior to 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof o...
Mozilla Bugzilla 2.18.6\\+
Mozilla Bugzilla 2.20.7
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.17.2
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.16.8
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.0.7
Mozilla Bugzilla 3.0.11
4
CVSSv2
CVE-2008-6098
Bugzilla 3.2 prior to 3.2 RC2, 3.0 prior to 3.0.6, 2.22 prior to 2.22.6, 2.20 prior to 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to...
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.9
Mozilla Bugzilla 2.18.8
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20.5
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.23.4
Mozilla Bugzilla 3.0.4
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.0.7
Mozilla Bugzilla 3.2
Mozilla Bugzilla 3.1.1
Mozilla Bugzilla 3.2.1
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.20
3.5
CVSSv2
CVE-2009-0481
Bugzilla 2.x prior to 2.22.7, 3.0 prior to 3.0.7, 3.2 prior to 3.2.1, and 3.3 prior to 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.16.10
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.18.9
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.22.5
Mozilla Bugzilla 2.22.6
Mozilla Bugzilla 3.2
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.16.11
3.5
CVSSv2
CVE-2008-2105
email_in.pl in Bugzilla 2.23.4, 3.0.x prior to 3.0.4, and 3.1.x prior to 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the Fr...
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.16.5
Mozilla Bugzilla 2.16.6
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.0.1
Mozilla Bugzilla 2.14
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.16.11
Mozilla Bugzilla 2.16.2
3.5
CVSSv2
CVE-2006-5453
Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x prior to 2.18.6, 2.20.x prior to 2.20.3, 2.22.x prior to 2.22.1, and 2.23.x prior to 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3...
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.18.5
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.23
Mozilla Bugzilla 2.23.1
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.23.2
2.6
CVSSv2
CVE-2015-8508
Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x prior to 4.2.16, 4.3.x and 4.4.x prior to 4.4.11, and 4.5.x and 5.0.x prior to 5.0.2, when a local dot configuration is used, allows remote malicious users to inject arbitrary web sc...
Mozilla Bugzilla 4.4.7
Mozilla Bugzilla 4.4.6
Mozilla Bugzilla 4.2.14
Mozilla Bugzilla 4.2.13
Mozilla Bugzilla 4.2.6
Mozilla Bugzilla 4.2.5
Mozilla Bugzilla 4.0.17
Mozilla Bugzilla 4.0.16
Mozilla Bugzilla 4.0.8
Mozilla Bugzilla 4.0.7
Mozilla Bugzilla 4.0
Mozilla Bugzilla 3.6.13
Mozilla Bugzilla 3.6.6
Mozilla Bugzilla 3.6.5
Mozilla Bugzilla 3.6.4
Mozilla Bugzilla 3.4.12
Mozilla Bugzilla 3.4.11
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.4.2
Mozilla Bugzilla 3.2.5
Mozilla Bugzilla 3.2.4
Mozilla Bugzilla 3.0.9
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-36920
buffer overflow
CVE-2024-36913
CVE-2024-5497
CVE-2024-23917
CVE-2024-4956
server-side request forgery
CVE-2024-35468
SSTI
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »