NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
79802  CVE-2002-0803  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.    Medium  2017-01-05  2008-09-10  View
79809  CVE-2002-0810  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.    Medium  2017-01-05  2008-09-05  View
79808  CVE-2002-0809  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.    7.5  High  2017-01-05  2008-09-05  View
79810  CVE-2002-0811  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.    7.5  High  2017-01-05  2008-09-10  View
79803  CVE-2002-0804  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.    7.5  High  2017-01-05  2008-09-05  View

Page 2266 of 17672, showing 5 records out of 88360 total, starting on record 11326, ending on 11330

Actions