NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 79807 | CVE-2002-0808 | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
| 15818 | CVE-2010-4568 | Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers to obtain access to arbitrary accounts via unspecified vectors, related to an insufficient number of calls to the srand function. | 2 | 7.5 | High | 2017-01-18 | 2011-10-25 | View | |
| 59642 | CVE-2006-0915 | Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 59641 | CVE-2006-0914 | Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error. | 2 | 5.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 80184 | CVE-2002-1198 | Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View |
Page 2267 of 17672, showing 5 records out of 88360 total, starting on record 11331, ending on 11335