Vulnerabilities > Mozilla > Bugzilla > High

DATE CVE VULNERABILITY TITLE RISK
2005-12-28 CVE-2005-4534 Unspecified vulnerability in Mozilla Bugzilla
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
network
low complexity
mozilla
7.5
2005-05-12 CVE-2005-1564 Remote Security vulnerability in Bugzilla
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
network
low complexity
mozilla
7.5
2004-08-18 CVE-2003-1046 Multiple vulnerability in Bugzilla
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
network
low complexity
mozilla
7.5
2004-08-18 CVE-2003-1044 Multiple vulnerability in Bugzilla
editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is being deleted, which allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.
network
low complexity
mozilla
7.5
2004-07-27 CVE-2004-0707 Unspecified vulnerability in Mozilla Bugzilla
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.
network
low complexity
mozilla
7.5
2004-07-27 CVE-2004-0703 Unspecified vulnerability in Mozilla Bugzilla
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.
network
low complexity
mozilla
7.5
2003-01-17 CVE-2003-0013 LocalConfig Backup File Disclosure vulnerability in Bugzilla
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.
network
low complexity
mozilla
7.5
2002-10-28 CVE-2002-1198 SQL Injection vulnerability in Bugzilla Account Creation
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.
network
low complexity
mozilla
7.5
2002-10-28 CVE-2002-1197 Unspecified vulnerability in Mozilla Bugzilla
bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.
network
low complexity
mozilla
7.5
2002-10-28 CVE-2002-1196 Unspecified vulnerability in Mozilla Bugzilla
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
network
low complexity
mozilla
7.5