Vulnerabilities > Mozilla > Bugzilla > 3.2.1

DATE CVE VULNERABILITY TITLE RISK
2009-04-01 CVE-2009-1213 Cross-Site Request Forgery (CSRF) vulnerability in Mozilla Bugzilla
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.
network
mozilla CWE-352
6.8
2009-02-09 CVE-2008-6098 Permissions, Privileges, and Access Controls vulnerability in Mozilla Bugzilla
Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to "approve."
network
low complexity
mozilla CWE-264
4.0
2009-02-09 CVE-2009-0486 Cross-Site Request Forgery (CSRF) vulnerability in Mozilla Bugzilla 3.0.7/3.2.1/3.3.2
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
network
low complexity
mozilla CWE-352
7.5