Vulnerabilities > Mozilla > Bugzilla > 3.4.2

DATE CVE VULNERABILITY TITLE RISK
2010-06-28 CVE-2010-1204 Permissions, Privileges, and Access Controls vulnerability in Mozilla Bugzilla
Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."
network
low complexity
mozilla CWE-264
5.0
2010-02-03 CVE-2009-3989 Permissions, Privileges, and Access Controls vulnerability in Mozilla Bugzilla
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
network
mozilla CWE-264
4.3
2010-02-03 CVE-2009-3387 Permissions, Privileges, and Access Controls vulnerability in Mozilla Bugzilla
Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
network
low complexity
mozilla CWE-264
5.0
2009-11-20 CVE-2009-3386 Information Exposure vulnerability in Mozilla Bugzilla
Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.
network
low complexity
mozilla CWE-200
5.0