Vulnerabilities > Mozilla > Bugzilla > 2.17.6

DATE CVE VULNERABILITY TITLE RISK
2004-07-27 CVE-2004-0702 Unspecified vulnerability in Mozilla Bugzilla
DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.
network
low complexity
mozilla
5.0
2002-12-31 CVE-2002-2260 Cross-Site Scripting vulnerability in Mozilla Bugzilla
Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.
network
mozilla CWE-79
4.3