Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2004-0702 DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote… Bugzilla Patch available Fix from $1,6002004-07-27 HIGH 7.5 CVE-2003-0594 Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal… Mozilla No fix yet Fix from $1,9502004-04-15 MEDIUM 6.8 CVE-2004-0191 Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page… Mozilla No fix yet Fix from $1,6002004-03-15 MEDIUM 5.0 CVE-2003-1492 Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with… Firefox No fix yet Fix from $1,6002003-12-31 CRITICAL 9.8 CVE-2003-0791 The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as … Mozilla after 1.4 Fix from $2,3002003-10-07 MEDIUM 6.8 CVE-2003-0602 Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitr… Bugzilla Patch available Fix from $1,6002003-08-27 HIGH 7.5 CVE-2003-0298 The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via ce… Mozilla Mitigation only Fix from $1,9502003-06-16 HIGH 7.5 CVE-2003-0152 Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user. Bonsai Patch available Fix from $1,9502003-04-02 MEDIUM 6.8 CVE-2003-0154 Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, … Bonsai Patch available Fix from $1,6002003-04-02 MEDIUM 5.0 CVE-2003-0153EPSS 6% bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3)… Bonsai Patch available Fix from $1,6002003-04-02 MEDIUM 5.0 CVE-2003-0155 bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication. Bonsai Patch available Fix from $1,6002003-04-02 HIGH 7.5 CVE-2003-0013 The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup c… Bugzilla Patch available Fix from $1,9502003-01-17 HIGH 7.5 CVE-2002-2061 Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code … Mozilla after 1.0 Fix from $1,9502002-12-31 MEDIUM 5.0 CVE-2002-2013 Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded nul… Mozilla Patch available Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2314EPSS 9% Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which caus… Mozilla Patch available Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2338 The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no … Mozilla Patch available Fix from $1,6002002-12-31 HIGH 7.5 CVE-2002-1308 Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar … Mozilla Mitigation only Fix from $1,9502002-11-29 HIGH 7.5 CVE-2002-1196 editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are s… Bugzilla Patch available Fix from $1,9502002-10-28 HIGH 7.5 CVE-2002-1197 bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell meta… Bugzilla Mitigation only Fix from $1,9502002-10-28 HIGH 7.5 CVE-2002-1198 Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to ex… Bugzilla Mitigation only Fix from $1,9502002-10-28 HIGH 7.5 CVE-2002-1091 Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero w… Mozilla Patch available Fix from $1,9502002-10-04 HIGH 7.5 CVE-2002-0804 Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictio… Bugzilla Patch available Fix from $1,9502002-08-12 HIGH 7.5 CVE-2002-0807 Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other… Bugzilla Patch available Fix from $1,9502002-08-12 HIGH 7.5 CVE-2002-0808 Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, … Bugzilla Patch available Fix from $1,9502002-08-12 HIGH 7.5 CVE-2002-0809 Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which cou… Bugzilla Patch available Fix from $1,9502002-08-12 HIGH 7.5 CVE-2002-0811 Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL in… Bugzilla Mitigation only Fix from $1,9502002-08-12 MEDIUM 5.0 CVE-2002-0803 Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request… Bugzilla Patch available Fix from $1,6002002-08-12 MEDIUM 5.0 CVE-2002-0810 Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensi… Bugzilla Patch available Fix from $1,6002002-08-12 MEDIUM 5.0 CVE-2002-0354 The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a clien… Mozilla Mitigation only Fix from $1,6002002-06-25 HIGH 7.5 CVE-2002-0593 Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit… Mozilla Patch available Fix from $1,9502002-06-18