Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bugzilla vulnerabilities and exploits
(subscribe to this query)
2.1
CVSSv2
CVE-2008-7292
Bugzilla 2.20.x prior to 2.20.5, 2.22.x prior to 2.22.3, and 3.0.x prior to 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different vulnerability than C...
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.20.4
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.22.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 3.0.0
Mozilla Bugzilla 3.0.2
Mozilla Bugzilla 3.0
Mozilla Bugzilla 3.0.1
2.6
CVSSv2
CVE-2005-2174
Bugzilla 2.17.x, 2.18 prior to 2.18.2, 2.19.x, and 2.20 prior to 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows malicious users to access information about the bug via buglist.cgi before MySQL replication is compl...
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.19.3
5
CVSSv2
CVE-2005-2173
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.19.1
4.3
CVSSv2
CVE-2012-4189
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x prior to 4.2.4, and 4.3.x and 4.4.x prior to 4.4rc1, allows remote malicious users to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, a...
Mozilla Bugzilla 4.1.2
Mozilla Bugzilla 4.1.3
Mozilla Bugzilla 4.1
Mozilla Bugzilla 4.1.1
Mozilla Bugzilla 4.2
Mozilla Bugzilla 4.2.1
Mozilla Bugzilla 4.2.2
Mozilla Bugzilla 4.2.3
Mozilla Bugzilla 4.3
Mozilla Bugzilla 4.3.1
Mozilla Bugzilla 4.3.2
Mozilla Bugzilla 4.3.3
5.5
CVSSv2
CVE-2006-0914
Bugzilla 2.16.10, 2.17 up to and including 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote malicious users to trigger a SQL error.
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.16.10
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18.4
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
5
CVSSv2
CVE-2009-3387
Bugzilla 3.3.1 up to and including 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote malicious users to obtain sensitive information via a request for a bug in oppo...
Mozilla Bugzilla 3.4.2
Mozilla Bugzilla 3.4.4
Mozilla Bugzilla 3.3.2
Mozilla Bugzilla 3.3.3
Mozilla Bugzilla 3.3.4
Mozilla Bugzilla 3.4
Mozilla Bugzilla 3.4.1
Mozilla Bugzilla 3.3.1
Mozilla Bugzilla 3.5.1
Mozilla Bugzilla 3.5.2
5
CVSSv2
CVE-2005-3138
Bugzilla 2.18rc1 up to and including 2.18.3, 2.19 up to and including 2.20rc2, and 2.21 allows remote malicious users to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.
Mozilla Bugzilla 2.18.1
Mozilla Bugzilla 2.18.2
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.19.3
Mozilla Bugzilla 2.18.3
Mozilla Bugzilla 2.18
Mozilla Bugzilla 2.20
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.19
Mozilla Bugzilla 2.19.1
4.3
CVSSv2
CVE-2007-0791
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and previous versions versions down to 2.20.1, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.23.3
5
CVSSv2
CVE-2009-3386
Template.pm in Bugzilla 3.3.2 up to and including 3.4.3 and 3.5 up to and including 3.5.1 allows remote malicious users to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
Mozilla Bugzilla 3.4
Mozilla Bugzilla 3.4.2
Mozilla Bugzilla 3.3.2
Mozilla Bugzilla 3.5
Mozilla Bugzilla 3.4.1
Mozilla Bugzilla 3.4.3
Mozilla Bugzilla 3.3.3
Mozilla Bugzilla 3.3.4
Mozilla Bugzilla 3.5.1
2.1
CVSSv2
CVE-2003-0012
The data collection script for Bugzilla 2.14.x prior to 2.14.5, 2.16.x prior to 2.16.2, and 2.17.x prior to 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.17
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »