Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.74% | — | Mozilla Bugzilla | 9/2/2009 | 16/6/2026 | Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers. | |
| Modificada | Alta (7.1) | 5.6% | — | Mozilla Bugzilla | 3/10/2008 | 16/6/2026 | Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element. | |
| Modificada | Baja (3.5) | 0.97% | — | Mozilla Bugzilla | 7/5/2008 | 16/6/2026 | email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers… | |
| Modificada | Media (4) | 0.93% | — | Mozilla Bugzilla | 7/5/2008 | 16/6/2026 | The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check. | |
| Modificada | Media (4.3) | 1.3% | — | Mozilla Bugzilla | 7/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list. | |
| Modificada | Alta (7.5) | 2.0% | — | Mozilla Bugzilla | 24/9/2007 | 16/6/2026 | The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation. | |
| Modificada | Media (5) | 1.6% | — | Mozilla Bugzilla | 27/8/2007 | 16/6/2026 | The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields. | |
| Modificada | Media (5) | 1.9% | — | Mozilla Bugzilla | 27/8/2007 | 16/6/2026 | email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters. | |
| Modificada | Media (4.3) | 1.4% | — | Mozilla Bugzilla | 27/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form." | |
| Modificada | Alta (7.5) | 1.4% | — | Mozilla Bugzilla | 6/2/2007 | 16/6/2026 | The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file. | |
| Modificada | Media (4.3) | 1.2% | — | Mozilla Bugzilla | 6/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.6) | 1.7% | — | Mozilla Bugzilla | 23/10/2006 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL. | |
| Modificada | Baja (3.5) | 2.0% | — | Mozilla Bugzilla | 23/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) page headers using the H1, H2, and H3 HTML tags in global/header.html.tmpl, (2)… | |
| Modificada | Media (5) | 2.1% | — | Mozilla Bugzilla | 23/10/2006 | 16/6/2026 | Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadline field by viewing the XML format of the bug in show_bug.cgi. | |
| Modificada | Media (4.3) | 1.5% | — | Mozilla Bugzilla | 16/5/2006 | 16/6/2026 | Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design… | |
| Modificada | Media (5.5) | 1.0% | — | Mozilla Bugzilla | 28/2/2006 | 16/6/2026 | SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi. | |
| Modificada | Alta (7.5) | 1.2% | — | Mozilla Bugzilla | 28/2/2006 | 16/6/2026 | Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error. | |
| Modificada | Alta (7.5) | 1.2% | — | Mozilla Bugzilla | 28/2/2006 | 16/6/2026 | Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain. | |
| Modificada | Media (5.5) | 1.2% | — | Mozilla Bugzilla | 28/2/2006 | 16/6/2026 | Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error. | |
| Modificada | Alta (7.5) | 1.5% | — | Mozilla Bugzilla | 28/12/2005 | 16/6/2026 | The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (5) | 1.1% | — | Mozilla Bugzilla | 5/10/2005 | 16/6/2026 | Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is accessible even when the requirelogin parameter is set. | |
| Modificada | Media (5) | 0.97% | — | Mozilla Bugzilla | 5/10/2005 | 16/6/2026 | Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set. | |
| Modificada | Media (5) | 0.93% | — | Mozilla Bugzilla | 8/7/2005 | 16/6/2026 | The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi. | |
| Modificada | Baja (2.6) | 0.85% | — | Mozilla Bugzilla | 8/7/2005 | 16/6/2026 | Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete. | |
| Modificada | Media (5) | 1.3% | — | Mozilla Bugzilla | 14/5/2005 | 16/6/2026 | Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products. |