Page 13 of 67 results (0.007 seconds)

CVSS: 2.6EPSS: 0%CPEs: 15EXPL: 0

Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete. • http://securitytracker.com/id?1014428 http://www.bugzilla.org/security/2.18.1 https://bugzilla.mozilla.org/show_bug.cgi?id=293159 •

CVSS: 5.0EPSS: 10%CPEs: 23EXPL: 0

Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products. • http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040 http://marc.info/?l=bugtraq&m=111592031902962&w=2 http://secunia.com/advisories/15338 http://www.bugzilla.org/security/2.16.8 http://www.osvdb.org/16425 http://www.securityfocus.com/bid/13606 http://www.vupen.com/english/advisories/2005/0533 https://bugzilla.mozilla.org/show_bug.cgi?id=287109 •

CVSS: 5.0EPSS: 0%CPEs: 25EXPL: 3

Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history. • http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=001040 http://marc.info/?l=bugtraq&m=111592031902962&w=2 http://secunia.com/advisories/15338 http://www.osvdb.org/16427 http://www.securityfocus.com/bid/13605 http://www.vupen.com/english/advisories/2005/0533 https://bugzilla.mozilla.org/show_bug.cgi?id=287436 •

CVSS: 7.5EPSS: 0%CPEs: 25EXPL: 2

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product. • http://marc.info/?l=bugtraq&m=111592031902962&w=2 http://secunia.com/advisories/15338 http://www.bugzilla.org/security/2.16.8 http://www.osvdb.org/16426 https://bugzilla.mozilla.org/show_bug.cgi?id=287109 https://exchange.xforce.ibmcloud.com/vulnerabilities/42797 •

CVSS: 5.0EPSS: 0%CPEs: 26EXPL: 0

show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information. • http://marc.info/?l=bugtraq&m=109872095201238&w=2 http://www.securityfocus.com/bid/11511 https://bugzilla.mozilla.org/show_bug.cgi?id=263780 https://exchange.xforce.ibmcloud.com/vulnerabilities/17841 •