NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
78836  CVE-2001-1402  Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi.    7.5  High  2017-01-05  2016-10-17  View
78837  CVE-2001-1403  Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser"s location bar.    7.5  High  2017-01-05  2016-10-17  View
78838  CVE-2001-1404  Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges.    7.5  High  2017-01-05  2016-10-17  View
78839  CVE-2001-1405  Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.    2.1  Low  2017-01-05  2016-10-17  View
78840  CVE-2001-1406  process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group"s restrictions, which might not be as stringent.    2.1  Low  2017-01-05  2016-10-17  View

Page 834 of 17672, showing 5 records out of 88360 total, starting on record 4166, ending on 4170

Actions