Vulnerabilities > Mozilla > Bugzilla > 3.4.13

DATE CVE VULNERABILITY TITLE RISK
2012-02-02 CVE-2012-0448 Improper Input Validation vulnerability in Mozilla Bugzilla
Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.
network
low complexity
mozilla CWE-20
4.0