CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9130  CVE-2004-0702  Candidate  DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.  Assigned (20040720)  None (candidate not yet proposed)    View
9131  CVE-2004-0703  Candidate  Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant memberships to groups that the user does not control.  Assigned (20040720)  None (candidate not yet proposed)    View
9132  CVE-2004-0704  Candidate  Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, when configured to hide products, allows remote attackers to view hidden products.  Assigned (20040720)  None (candidate not yet proposed)    View
9133  CVE-2004-0705  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.  Assigned (20040720)  None (candidate not yet proposed)    View
9134  CVE-2004-0706  Candidate  Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.  Assigned (20040720)  None (candidate not yet proposed)    View

Page 915 of 20943, showing 5 records out of 104715 total, starting on record 4571, ending on 4575

Actions