Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bugzilla MEDIUM 5.0
CVE-2004-0702

DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote…

Patch available
Fix from $1,600 2004-07-27
Mozilla HIGH 7.5
CVE-2003-0594

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal…

No fix yet
Fix from $1,950 2004-04-15
Mozilla MEDIUM 6.8
CVE-2004-0191

Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page…

No fix yet
Fix from $1,600 2004-03-15
Firefox MEDIUM 5.0
CVE-2003-1492

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with…

No fix yet
Fix from $1,600 2003-12-31
Mozilla CRITICAL 9.8
CVE-2003-0791

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as …

Fix: after 1.4
Fix from $2,300 2003-10-07
Bugzilla MEDIUM 6.8
CVE-2003-0602

Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitr…

Patch available
Fix from $1,600 2003-08-27
Mozilla HIGH 7.5
CVE-2003-0298

The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via ce…

Mitigation only
Fix from $1,950 2003-06-16
Bonsai HIGH 7.5
CVE-2003-0152

Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.

Patch available
Fix from $1,950 2003-04-02
Bonsai MEDIUM 6.8
CVE-2003-0154

Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, …

Patch available
Fix from $1,600 2003-04-02
Bonsai MEDIUM 5.0
CVE-2003-0153EPSS 6%

bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3)…

Patch available
Fix from $1,600 2003-04-02
Bonsai MEDIUM 5.0
CVE-2003-0155

bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.

Patch available
Fix from $1,600 2003-04-02
Bugzilla HIGH 7.5
CVE-2003-0013

The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup c…

Patch available
Fix from $1,950 2003-01-17
Mozilla HIGH 7.5
CVE-2002-2061

Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code …

Fix: after 1.0
Fix from $1,950 2002-12-31
Mozilla MEDIUM 5.0
CVE-2002-2013

Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded nul…

Patch available
Fix from $1,600 2002-12-31
Mozilla MEDIUM 5.0
CVE-2002-2314EPSS 9%

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which caus…

Patch available
Fix from $1,600 2002-12-31
Mozilla MEDIUM 5.0
CVE-2002-2338

The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no …

Patch available
Fix from $1,600 2002-12-31
Mozilla HIGH 7.5
CVE-2002-1308

Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar …

Mitigation only
Fix from $1,950 2002-11-29
Bugzilla HIGH 7.5
CVE-2002-1196

editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are s…

Patch available
Fix from $1,950 2002-10-28
Bugzilla HIGH 7.5
CVE-2002-1197

bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell meta…

Mitigation only
Fix from $1,950 2002-10-28
Bugzilla HIGH 7.5
CVE-2002-1198

Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to ex…

Mitigation only
Fix from $1,950 2002-10-28
Mozilla HIGH 7.5
CVE-2002-1091

Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero w…

Patch available
Fix from $1,950 2002-10-04
Bugzilla HIGH 7.5
CVE-2002-0804

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictio…

Patch available
Fix from $1,950 2002-08-12
Bugzilla HIGH 7.5
CVE-2002-0807

Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other…

Patch available
Fix from $1,950 2002-08-12
Bugzilla HIGH 7.5
CVE-2002-0808

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, …

Patch available
Fix from $1,950 2002-08-12
Bugzilla HIGH 7.5
CVE-2002-0809

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which cou…

Patch available
Fix from $1,950 2002-08-12
Bugzilla HIGH 7.5
CVE-2002-0811

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL in…

Mitigation only
Fix from $1,950 2002-08-12
Bugzilla MEDIUM 5.0
CVE-2002-0803

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request…

Patch available
Fix from $1,600 2002-08-12
Bugzilla MEDIUM 5.0
CVE-2002-0810

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensi…

Patch available
Fix from $1,600 2002-08-12
Mozilla MEDIUM 5.0
CVE-2002-0354

The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a clien…

Mitigation only
Fix from $1,600 2002-06-25
Mozilla HIGH 7.5
CVE-2002-0593

Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit…

Patch available
Fix from $1,950 2002-06-18