VendorsMozillabugzilla3.2.2
Vulnerabilities

Mozilla Bugzilla 3.2.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2012-0466
template/en/default/list/list.js.tmpl in Bugzilla 2.x and 3.x before 3.6.9, 3.7.x and 4.0.x before 4.0.6, and 4.1.x and 4.2.x before 4.2.1 does not properly handle multiple logins, which allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive bug information via a crafted web page.
Published 2012-04-27 · Modified
4.0EPSS 0.008
CVE-2010-3172
CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL.
Published 2010-11-05 · Modified
2.6EPSS 0.018
← Prev2 / 2