Vulnerabilities > Mozilla > Bugzilla > High

DATE CVE VULNERABILITY TITLE RISK
2015-09-14 CVE-2015-4499 Improper Input Validation vulnerability in Mozilla Bugzilla
Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.
network
low complexity
mozilla CWE-20
7.5
2011-01-28 CVE-2010-4568 Permissions, Privileges, and Access Controls vulnerability in Mozilla Bugzilla
Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand function.
network
low complexity
mozilla CWE-264
7.5
2009-09-15 CVE-2009-3165 SQL Injection vulnerability in Mozilla Bugzilla
SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
network
low complexity
mozilla CWE-89
7.5
2009-09-15 CVE-2009-3125 SQL Injection vulnerability in Mozilla Bugzilla
SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
network
low complexity
mozilla CWE-89
7.5
2009-02-09 CVE-2009-0486 Cross-Site Request Forgery (CSRF) vulnerability in Mozilla Bugzilla 3.0.7/3.2.1/3.3.2
Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.
network
low complexity
mozilla CWE-352
7.5
2008-10-03 CVE-2008-4437 Path Traversal vulnerability in Mozilla Bugzilla
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a ..
network
mozilla CWE-22
7.1
2007-09-24 CVE-2007-5038 Permissions, Privileges, and Access Controls vulnerability in Mozilla Bugzilla
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.
network
low complexity
mozilla CWE-264
7.5
2007-02-06 CVE-2007-0792 HTML Injection And Information disclosure vulnerability in Mozilla Bugzilla 2.23.3
The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
network
low complexity
mozilla
7.5
2006-02-28 CVE-2006-0916 Information Disclosure vulnerability in Bugzilla User Credentials
Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.
network
low complexity
mozilla
7.5
2006-02-28 CVE-2006-0915 Unspecified vulnerability in Mozilla Bugzilla 2.16.10
Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.
network
low complexity
mozilla
7.5