Mozilla

Bugzilla

145 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 09.08.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE...

  • EPSS 0.65%
  • Veröffentlicht 09.08.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to the confirmation e-mail address (aka old_email field) for e-mail chang...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 09.08.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search. NOTE: this vuln...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 09.08.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a differ...

  • EPSS 0.83%
  • Veröffentlicht 28.01.2011 16:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scriptin...

  • EPSS 0.83%
  • Veröffentlicht 28.01.2011 16:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks via...

  • EPSS 1.87%
  • Veröffentlicht 28.01.2011 16:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to a...

  • EPSS 0.73%
  • Veröffentlicht 28.01.2011 16:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.

  • EPSS 0.73%
  • Veröffentlicht 28.01.2011 16:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI...

  • EPSS 0.83%
  • Veröffentlicht 28.01.2011 16:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

CRLF injection vulnerability in chart.cgi in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the query s...