CVE-2011-0046
- EPSS 0.43%
- Published 28.01.2011 16:00:02
- Last modified 11.04.2025 00:51:21
Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) ...
CVE-2010-3172
- EPSS 0.73%
- Published 05.11.2010 17:00:02
- Last modified 11.04.2025 00:51:21
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HT...
- EPSS 0.85%
- Published 05.11.2010 17:00:02
- Last modified 11.04.2025 00:51:21
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
- EPSS 0.84%
- Published 16.08.2010 15:14:12
- Last modified 11.04.2025 00:51:21
Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and ...
CVE-2010-2757
- EPSS 1.24%
- Published 16.08.2010 15:14:12
- Last modified 11.04.2025 00:51:21
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users wi...
- EPSS 0.72%
- Published 16.08.2010 15:14:12
- Last modified 11.04.2025 00:51:21
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified...
- EPSS 1.64%
- Published 16.08.2010 15:14:12
- Last modified 11.04.2025 00:51:21
Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases, which allows remote authenticated users to cause a...
- EPSS 0.47%
- Published 28.06.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
CVE-2010-2470
- EPSS 0.04%
- Published 28.06.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading f...
CVE-2010-0180
- EPSS 0.05%
- Published 28.06.2010 17:30:00
- Last modified 11.04.2025 00:51:21
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database passw...