NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68801 | CVE-2005-3139 | Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68800 | CVE-2005-3138 | Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 64055 | CVE-2006-5454 | Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadline field by viewing the XML format of the bug in show_bug.cgi. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 67876 | CVE-2005-2174 | Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete. | 2 | 2.6 | Low | 2017-01-03 | 2008-09-05 | View | |
| 71133 | CVE-2004-0706 | Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View |
Page 15404 of 17672, showing 5 records out of 88360 total, starting on record 77016, ending on 77020