Search CVE reports


Toggle filters

41 – 50 of 97 results


CVE-2010-4570

Low priority
Not affected

Cross-site scripting (XSS) vulnerability in the duplicate-detection functionality in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the summary field, related to the...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-4569

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in Bugzilla 3.7.1, 3.7.2, 3.7.3, and 4.0rc1 allows remote attackers to inject arbitrary web script or HTML via the real name field of a user account, related to the AutoComplete widget in YUI.

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-4568

Medium priority
Ignored

Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for cookies and tokens, which allows remote attackers...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-4567

Medium priority
Ignored

Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 does not properly handle whitespace preceding a (1) javascript: or (2) data: URI, which allows remote attackers to conduct cross-site...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-3764

Low priority
Ignored

The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-3172

Medium priority
Ignored

CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-2759

Low priority
Ignored

Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases, which allows...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-2758

Low priority
Ignored

Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-2757

Medium priority
Ignored

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages

CVE-2010-2756

Low priority
Ignored

Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the group memberships of arbitrary users via vectors involving the Search interface,...

1 affected package

bugzilla

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bugzilla
Show less packages