CVE-2012-4199
- EPSS 0.32%
- Veröffentlicht 16.11.2012 12:24:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates JavaScript function calls containing private product names or private ...
CVE-2012-5883
- EPSS 0.61%
- Veröffentlicht 16.11.2012 12:24:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to i...
- EPSS 0.26%
- Veröffentlicht 16.11.2012 12:24:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-20...
- EPSS 0.6%
- Veröffentlicht 04.09.2012 11:04:50
- Zuletzt bearbeitet 11.04.2025 00:51:21
Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a username, which might allow remote attackers to inject data into an LD...
- EPSS 0.26%
- Veröffentlicht 04.09.2012 11:04:50
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to rea...
CVE-2012-1968
- EPSS 0.28%
- Veröffentlicht 30.07.2012 13:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information b...
CVE-2012-1969
- EPSS 0.39%
- Veröffentlicht 30.07.2012 13:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment...
CVE-2012-0465
- EPSS 0.24%
- Veröffentlicht 27.04.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the...
- EPSS 0.32%
- Veröffentlicht 27.04.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) a...
CVE-2012-0453
- EPSS 0.13%
- Veröffentlicht 25.02.2012 04:21:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the produc...