VendorsMozillabugzilla3.0.3
Vulnerabilities

Mozilla Bugzilla 3.0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2012-0466
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page.
Published 2012-04-27 · Modified
4.0EPSS 0.008
CVE-2009-0481
Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.
Published 2009-02-09 · Modified
3.5EPSS 0.007
← Prev2 / 2