Show filters
41 Total Results
Displaying 31-40 of 41
Sort by:
Attacker Value
Unknown

CVE-2011-2379

Disclosure Date: August 09, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9 or Safari before 5.0.6 is used for Raw Unified mode, allows remote attackers to inject arbitrary web script or HTML via a crafted patch, related to content sniffing.
0
Attacker Value
Unknown

CVE-2010-4570

Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the DataTable widget in YUI.
0
Attacker Value
Unknown

CVE-2010-4569

Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.
0
Attacker Value
Unknown

CVE-2010-3764

Disclosure Date: November 05, 2010 (last updated October 04, 2023)
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
0
Attacker Value
Unknown

CVE-2010-2757

Disclosure Date: August 16, 2010 (last updated October 04, 2023)
The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users without discovery.
0
Attacker Value
Unknown

CVE-2010-2758

Disclosure Date: August 16, 2010 (last updated October 04, 2023)
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
0
Attacker Value
Unknown

CVE-2010-2759

Disclosure Date: August 16, 2010 (last updated October 04, 2023)
Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases, which allows remote authenticated users to cause a denial of service (bug invisibility) via a crafted comment.
0
Attacker Value
Unknown

CVE-2010-2756

Disclosure Date: August 16, 2010 (last updated October 04, 2023)
Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface, boolean charts, and group-based pronouns.
0
Attacker Value
Unknown

CVE-2010-0180

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.
0
Attacker Value
Unknown

CVE-2010-1204

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
0