CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4206 | CVE-2001-1403 | Candidate | Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser"s location bar. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-location-bar-passwords(10484) | View |
4207 | CVE-2001-1404 | Candidate | Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-plaintext-passwords(10483) | View |
4208 | CVE-2001-1405 | Candidate | Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Cox> Right CD? | Frech> XF:bugzilla-sanitycheck-dos(10481) | View |
4209 | CVE-2001-1406 | Entry | process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group"s restrictions, which might not be as stringent. | View | |||
4210 | CVE-2001-1407 | Entry | Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug. | View |
Page 842 of 20943, showing 5 records out of 104715 total, starting on record 4206, ending on 4210