CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5196  CVE-2002-0806  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.        View
5197  CVE-2002-0807  Candidate  Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.  Modified (20071101)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:bugzilla-real-name-xss(9304)  View
5198  CVE-2002-0808  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.        View
5199  CVE-2002-0809  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.        View
5200  CVE-2002-0810  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.        View

Page 1040 of 20943, showing 5 records out of 104715 total, starting on record 5196, ending on 5200

Actions