Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2002-0007 CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not… Bugzilla after 2.14.1 Fix from $1,9502002-01-31 HIGH 7.5 CVE-2002-0008 Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead … Bugzilla after 2.14.1 Fix from $1,9502002-01-31 HIGH 7.5 CVE-2002-0010 Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.… Bugzilla after 2.14.1 Fix from $1,9502002-01-31 MEDIUM 5.0 CVE-2002-0009 show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by subm… Bugzilla after 2.14.1 Fix from $1,6002002-01-31 MEDIUM 5.0 CVE-2002-0011 Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login. Bugzilla after 2.14.1 Fix from $1,6002002-01-31 MEDIUM 5.0 CVE-2001-1490EPSS 6% Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images. Mozilla No fix yet Fix from $1,6002001-12-31 HIGH 7.5 CVE-2001-1401 Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modif… Bugzilla Patch available Fix from $1,9502001-09-10 HIGH 7.5 CVE-2001-1402 Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-s… Bugzilla Patch available Fix from $1,9502001-09-10 HIGH 7.5 CVE-2001-1403 Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the w… Bugzilla Patch available Fix from $1,9502001-09-10 HIGH 7.5 CVE-2001-1404 Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileg… Bugzilla Patch available Fix from $1,9502001-09-10 HIGH 7.5 CVE-2001-1407 Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user… Bugzilla Patch available Fix from $1,9502001-09-10 HIGH 7.5 CVE-2001-0329 Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla… Bugzilla Patch available Fix from $1,9502001-06-27 HIGH 7.5 CVE-2001-0330 Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the glob… Bugzilla Patch available Fix from $1,9502001-06-27 MEDIUM 5.0 CVE-2000-0655EPSS 13% Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing… Mozilla Patch available Fix from $1,6002000-07-25 HIGH 7.5 CVE-2000-0421 The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters. Bugzilla Mitigation only Fix from $1,9502000-05-11