VendorsMozillabugzilla3.6.1
Vulnerabilities

Mozilla Bugzilla 3.6.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2011-2977
Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists because of a regression in 3.6.
Published 2011-08-09 · Modified
2.1EPSS 0.003
CVE-2010-2470
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.
Published 2010-06-28 · Modified
1.9EPSS 0.003
← Prev2 / 2