Vulnerabilities > Mozilla > Bugzilla > Medium

DATE CVE VULNERABILITY TITLE RISK
2002-08-12 CVE-2002-0805 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.
local
low complexity
mozilla
4.6
2002-08-12 CVE-2002-0803 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.
network
low complexity
mozilla
5.0
2002-01-31 CVE-2002-0011 Unspecified vulnerability in Mozilla Bugzilla
Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.
network
low complexity
mozilla
5.0
2002-01-31 CVE-2002-0009 Unspecified vulnerability in Mozilla Bugzilla
show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.
network
low complexity
mozilla
5.0