CVE-2012-4199
- EPSS 0.32%
- Published 16.11.2012 12:24:24
- Last modified 11.04.2025 00:51:21
template/en/default/bug/field-events.js.tmpl in Bugzilla 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 generates JavaScript function calls containing private product names or private ...
CVE-2012-5883
- EPSS 0.61%
- Published 16.11.2012 12:24:24
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to i...
- EPSS 0.26%
- Published 16.11.2012 12:24:24
- Last modified 11.04.2025 00:51:21
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-20...
- EPSS 0.6%
- Published 04.09.2012 11:04:50
- Last modified 11.04.2025 00:51:21
Auth/Verify/LDAP.pm in Bugzilla 2.x and 3.x before 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 does not restrict the characters in a username, which might allow remote attackers to inject data into an LD...
- EPSS 0.26%
- Published 04.09.2012 11:04:50
- Last modified 11.04.2025 00:51:21
Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to rea...
CVE-2012-1968
- EPSS 0.28%
- Published 30.07.2012 13:55:10
- Last modified 11.04.2025 00:51:21
Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information b...
CVE-2012-1969
- EPSS 0.39%
- Published 30.07.2012 13:55:10
- Last modified 11.04.2025 00:51:21
The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment...
CVE-2012-0465
- EPSS 0.24%
- Published 27.04.2012 20:55:01
- Last modified 11.04.2025 00:51:21
Bugzilla 3.5.x and 3.6.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1, when the inbound_proxies option is enabled, does not properly validate the X-Forwarded-For HTTP header, which allows remote attackers to bypass the...
- EPSS 0.32%
- Published 27.04.2012 20:55:01
- Last modified 11.04.2025 00:51:21
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) a...
CVE-2012-0453
- EPSS 0.13%
- Published 25.02.2012 04:21:42
- Last modified 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the produc...