CVE-2011-0046
- EPSS 0.43%
- Veröffentlicht 28.01.2011 16:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) ...
CVE-2010-3172
- EPSS 0.73%
- Veröffentlicht 05.11.2010 17:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HT...
- EPSS 0.85%
- Veröffentlicht 05.11.2010 17:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
- EPSS 0.84%
- Veröffentlicht 16.08.2010 15:14:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and ...
CVE-2010-2757
- EPSS 1.24%
- Veröffentlicht 16.08.2010 15:14:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users wi...
- EPSS 0.72%
- Veröffentlicht 16.08.2010 15:14:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified...
- EPSS 1.64%
- Veröffentlicht 16.08.2010 15:14:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases, which allows remote authenticated users to cause a...
- EPSS 0.47%
- Veröffentlicht 28.06.2010 17:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
CVE-2010-2470
- EPSS 0.04%
- Veröffentlicht 28.06.2010 17:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading f...
CVE-2010-0180
- EPSS 0.05%
- Veröffentlicht 28.06.2010 17:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database passw...