Vulnerabilities > Mozilla > Bugzilla > 2.21.2

DATE CVE VULNERABILITY TITLE RISK
2008-05-07 CVE-2008-2103 Cross-Site Scripting vulnerability in Mozilla Bugzilla
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.
network
mozilla CWE-79
4.3
2007-02-06 CVE-2007-0791 HTML Injection And Information disclosure vulnerability in Mozilla Bugzilla
Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
mozilla
4.3
2006-10-23 CVE-2006-5455 Input Validation and Information disclosure vulnerability in Mozilla Bugzilla
Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.
network
high complexity
mozilla
2.6
2006-02-28 CVE-2006-0916 Information Disclosure vulnerability in Bugzilla User Credentials
Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.
network
low complexity
mozilla
7.5