Mozilla

Bugzilla

145 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Published 27.07.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.

  • EPSS 0.07%
  • Published 27.07.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.

  • EPSS 0.5%
  • Published 27.07.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.

  • EPSS 1.01%
  • Published 27.08.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME...

  • EPSS 0.09%
  • Published 27.08.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.

  • EPSS 0.06%
  • Published 17.01.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.

  • EPSS 1.11%
  • Published 17.01.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remo...

  • EPSS 0.33%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.

  • EPSS 0.43%
  • Published 28.10.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to...

  • EPSS 2.12%
  • Published 28.10.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.