Bugzilla
Vendor:
First CVE: May 11, 2000 · Active for 26 years
151
Total CVEs
More Total CVEs than 99% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bugzilla over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2000
26 years ago
Most Recent CVE
Apr 29, 2019
2,644 days ago
CVE Severity & Scoring
Bugzilla151 CVEs
11%
62%
26%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (2.6%)
Unknown147 (97.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.0%)
High1 (0.7%)
Unknown147 (97.4%)
User Interaction
None0 (0.0%)
Unknown147 (97.4%)
Required4 (2.6%)
Privileges Required
Low1 (0.7%)
High0 (0.0%)
None3 (2.0%)
Unknown147 (97.4%)
Top CVEs
Signals from CVEs in this product scope (151 CVEs).
151 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1043HIGH SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via t | Aug 18, 2004 | 10.0 | 31 | NO | NO |
CVE-2002-0007HIGH CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which caus | Jan 31, 2002 | 10.0 | 30 | NO | NO |
CVE-2008-4437HIGH Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files vi | Oct 3, 2008 | 7.1 | 29 | NO | YES |
CVE-2001-0329HIGH Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, | Jun 27, 2001 | 7.5 | 29 | NO | YES |
CVE-2018-5123HIGH A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4. | Apr 29, 2019 | 8.8 | 27 | NO | NO |
CVE-2004-0769HIGH Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" o | Aug 18, 2004 | 10.0 | 27 | NO | NO |
CVE-2003-1042HIGH SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the produ | Aug 18, 2004 | 10.0 | 25 | NO | NO |
CVE-2015-4499HIGH Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows | Sep 14, 2015 | 7.5 | 24 | NO | NO |
CVE-2010-4568HIGH Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for c | Jan 28, 2011 | 7.5 | 24 | NO | NO |
CVE-2003-1046HIGH describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descr | Aug 18, 2004 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (151 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (151 CVEs).
Media Mentions
Signals from CVEs in this product scope (151 CVEs).
Top CNAs Publishing CVEs For Bugzilla
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.2 | 1 | 6.1 | 1.5% | 0 | 0 |
| 5.0.1 | 3 | 4.8 | 1.6% | 0 | 0 |
| 5.0 | 4 | 5.7 | 1.8% | 0 | 0 |
| 4.5.6 | 2 | 6.3 | 1.8% | 0 | 0 |
| 4.5.5 | 5 | 5.2 | 1.8% | 0 | 0 |
| 4.5.4 | 6 | 5.0 | 1.6% | 0 | 0 |
| 4.5.3 | 6 | 5.0 | 1.6% | 0 | 0 |
| 4.5.2 | 7 | 4.9 | 1.6% | 0 | 0 |
| 4.5.1 | 7 | 4.9 | 1.6% | 0 | 0 |
| 4.5 | 6 | 4.7 | 1.6% | 0 | 0 |
| 4.4.9 | 4 | 5.5 | 2.1% | 0 | 0 |
| 4.4.8 | 4 | 5.5 | 2.1% | 0 | 0 |
| 4.4.7 | 4 | 5.5 | 2.1% | 0 | 0 |
| 4.4.6 | 5 | 5.7 | 2.1% | 0 | 0 |
| 4.4.5 | 8 | 5.2 | 2.0% | 0 | 0 |
| 4.4.4 | 9 | 5.1 | 1.8% | 0 | 0 |
| 4.4.3 | 9 | 5.1 | 1.8% | 0 | 0 |
| 4.4.2 | 10 | 5.0 | 1.8% | 0 | 0 |
| 4.4.11 | 1 | 6.1 | 1.5% | 0 | 0 |
| 4.4.10 | 3 | 4.8 | 1.6% | 0 | 0 |