- EPSS 0.39%
- Veröffentlicht 20.04.2014 01:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arr...
CVE-2013-1734
- EPSS 0.12%
- Veröffentlicht 24.10.2013 10:53:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users fo...
CVE-2013-1742
- EPSS 0.75%
- Veröffentlicht 24.10.2013 10:53:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via t...
CVE-2013-1743
- EPSS 0.9%
- Veröffentlicht 24.10.2013 10:53:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled d...
CVE-2013-1733
- EPSS 0.12%
- Veröffentlicht 24.10.2013 10:53:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs via vectors involving a midair-collision token.
- EPSS 0.28%
- Veröffentlicht 24.02.2013 11:48:25
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers...
CVE-2013-0785
- EPSS 0.3%
- Veröffentlicht 24.02.2013 11:48:22
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in show_bug.cgi in Bugzilla before 3.6.13, 3.7.x and 4.0.x before 4.0.10, 4.1.x and 4.2.x before 4.2.5, and 4.3.x and 4.4.x before 4.4rc2 allows remote attackers to inject arbitrary web script or HTML via the ...
CVE-2012-4189
- EPSS 0.3%
- Veröffentlicht 16.11.2012 12:24:24
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in Bugzilla 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of...
- EPSS 0.32%
- Veröffentlicht 16.11.2012 12:24:24
- Zuletzt bearbeitet 29.04.2026 01:13:23
Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 allows remote attackers to read attachment descriptions from private bugs vi...
- EPSS 0.18%
- Veröffentlicht 16.11.2012 12:24:24
- Zuletzt bearbeitet 29.04.2026 01:13:23
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allow...