NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 77808 | CVE-2001-0330 | Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
| 77807 | CVE-2001-0329 | Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
| 67290 | CVE-2005-1563 | Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 79804 | CVE-2002-0805 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 79805 | CVE-2002-0806 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option. | 2 | 2.1 | Low | 2017-01-05 | 2008-09-05 | View |
Page 2265 of 17672, showing 5 records out of 88360 total, starting on record 11321, ending on 11325