NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
78836 | CVE-2001-1402 | Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
78837 | CVE-2001-1403 | Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser"s location bar. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
78838 | CVE-2001-1404 | Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges. | 2 | 7.5 | High | 2017-01-05 | 2016-10-17 | View | |
78839 | CVE-2001-1405 | Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi. | 2 | 2.1 | Low | 2017-01-05 | 2016-10-17 | View | |
78840 | CVE-2001-1406 | process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group"s restrictions, which might not be as stringent. | 2 | 2.1 | Low | 2017-01-05 | 2016-10-17 | View |
Page 834 of 17672, showing 5 records out of 88360 total, starting on record 4166, ending on 4170