NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
79810 | CVE-2002-0811 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
79809 | CVE-2002-0810 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
79808 | CVE-2002-0809 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
79807 | CVE-2002-0808 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
79806 | CVE-2002-0807 | Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View |
Page 16645 of 17672, showing 5 records out of 88360 total, starting on record 83221, ending on 83225