5

CVE-2010-1204

Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."

Data is provided by the National Vulnerability Database (NVD)
MozillaBugzilla Version2.17.1
MozillaBugzilla Version2.17.3
MozillaBugzilla Version2.17.4
MozillaBugzilla Version2.17.5
MozillaBugzilla Version2.17.6
MozillaBugzilla Version2.17.7
MozillaBugzilla Version3.0
MozillaBugzilla Version3.0.1
MozillaBugzilla Version3.0.2
MozillaBugzilla Version3.0.3
MozillaBugzilla Version3.0.4
MozillaBugzilla Version3.0.5
MozillaBugzilla Version3.0.6
MozillaBugzilla Version3.0.7
MozillaBugzilla Version3.0.8
MozillaBugzilla Version3.0.9
MozillaBugzilla Version3.0.10
MozillaBugzilla Version3.0.11
MozillaBugzilla Version3.1.1
MozillaBugzilla Version3.1.2
MozillaBugzilla Version3.1.3
MozillaBugzilla Version3.1.4
MozillaBugzilla Version3.2
MozillaBugzilla Version3.2.1
MozillaBugzilla Version3.2.2
MozillaBugzilla Version3.2.3
MozillaBugzilla Version3.2.4
MozillaBugzilla Version3.2.5
MozillaBugzilla Version3.2.6
MozillaBugzilla Version3.3.1
MozillaBugzilla Version3.3.3
MozillaBugzilla Version3.3.4
MozillaBugzilla Version3.4
MozillaBugzilla Version3.4.1
MozillaBugzilla Version3.4.2
MozillaBugzilla Version3.4.3
MozillaBugzilla Version3.4.4
MozillaBugzilla Version3.4.5
MozillaBugzilla Version3.4.6
MozillaBugzilla Version3.5.1
MozillaBugzilla Version3.5.2
MozillaBugzilla Version3.5.3
MozillaBugzilla Version3.6
MozillaBugzilla Version3.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.47% 0.617
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N