Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bugzilla HIGH 10.0
CVE-2002-0007

CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not…

Fix: after 2.14.1
Fix from $1,950 2002-01-31
Bugzilla HIGH 7.5
CVE-2002-0008

Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead …

Fix: after 2.14.1
Fix from $1,950 2002-01-31
Bugzilla HIGH 7.5
CVE-2002-0010

Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.…

Fix: after 2.14.1
Fix from $1,950 2002-01-31
Bugzilla MEDIUM 5.0
CVE-2002-0009

show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by subm…

Fix: after 2.14.1
Fix from $1,600 2002-01-31
Bugzilla MEDIUM 5.0
CVE-2002-0011

Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.

Fix: after 2.14.1
Fix from $1,600 2002-01-31
Mozilla MEDIUM 5.0
CVE-2001-1490EPSS 6%

Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

No fix yet
Fix from $1,600 2001-12-31
Bugzilla HIGH 7.5
CVE-2001-1401

Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modif…

Patch available
Fix from $1,950 2001-09-10
Bugzilla HIGH 7.5
CVE-2001-1402

Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-s…

Patch available
Fix from $1,950 2001-09-10
Bugzilla HIGH 7.5
CVE-2001-1403

Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the w…

Patch available
Fix from $1,950 2001-09-10
Bugzilla HIGH 7.5
CVE-2001-1404

Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileg…

Patch available
Fix from $1,950 2001-09-10
Bugzilla HIGH 7.5
CVE-2001-1407

Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user…

Patch available
Fix from $1,950 2001-09-10
Bugzilla HIGH 7.5
CVE-2001-0329

Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla…

Patch available
Fix from $1,950 2001-06-27
Bugzilla HIGH 7.5
CVE-2001-0330

Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the glob…

Patch available
Fix from $1,950 2001-06-27
Mozilla MEDIUM 5.0
CVE-2000-0655EPSS 13%

Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing…

Patch available
Fix from $1,600 2000-07-25
Bugzilla HIGH 7.5
CVE-2000-0421

The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.

Mitigation only
Fix from $1,950 2000-05-11