NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
79805  CVE-2002-0806  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.    2.1  Low  2017-01-05  2008-09-05  View
79804  CVE-2002-0805  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.    4.6  Medium  2017-01-05  2008-09-05  View
67290  CVE-2005-1563  Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.    Medium  2017-01-03  2016-10-17  View
77807  CVE-2001-0329  Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.    7.5  High  2017-01-05  2008-09-10  View
77808  CVE-2001-0330  Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.    7.5  High  2017-01-05  2008-09-05  View

Page 15408 of 17672, showing 5 records out of 88360 total, starting on record 77036, ending on 77040

Actions