Vulnerabilities > Mozilla

DATE CVE VULNERABILITY TITLE RISK
2002-08-12 CVE-2002-0808 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.
network
low complexity
mozilla
7.5
2002-08-12 CVE-2002-0807 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.
network
low complexity
mozilla
7.5
2002-08-12 CVE-2002-0806 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
local
low complexity
mozilla
2.1
2002-08-12 CVE-2002-0805 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.
local
low complexity
mozilla
4.6
2002-08-12 CVE-2002-0804 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.
network
low complexity
mozilla
7.5
2002-08-12 CVE-2002-0803 Unspecified vulnerability in Mozilla Bugzilla 2.14/2.14.1/2.16
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.
network
low complexity
mozilla
5.0
2002-06-25 CVE-2002-0354 The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
network
low complexity
mozilla netscape
5.0
2002-06-18 CVE-2002-0594 Local File Detection vulnerability in Netscape/Mozilla/Galeon
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
network
low complexity
galeon mozilla netscape
5.0
2002-06-18 CVE-2002-0593 Buffer Overflow vulnerability in Netscape/Mozilla IRC
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
network
low complexity
mozilla netscape
7.5
2002-01-31 CVE-2002-0011 Unspecified vulnerability in Mozilla Bugzilla
Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.
network
low complexity
mozilla
5.0