NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
68801  CVE-2005-3139  Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.    Medium  2017-07-18  2017-07-10  View
68800  CVE-2005-3138  Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set.    Medium  2017-07-18  2017-07-10  View
64055  CVE-2006-5454  Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadline field by viewing the XML format of the bug in show_bug.cgi.    Medium  2016-12-20  2011-03-07  View
67876  CVE-2005-2174  Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.    2.6  Low  2017-01-03  2008-09-05  View
71133  CVE-2004-0706  Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.    2.1  Low  2017-07-18  2017-07-10  View

Page 15404 of 17672, showing 5 records out of 88360 total, starting on record 77016, ending on 77020

Actions