Bugzilla

Vendor:

First CVE: May 11, 2000 · Active for 26 years

151
Total CVEs
More Total CVEs than 99% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Bugzilla over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2000
26 years ago
Most Recent CVE
Apr 29, 2019
2,644 days ago

CVE Severity & Scoring

Bugzilla151 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (2.6%)
Unknown147 (97.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.0%)
High1 (0.7%)
Unknown147 (97.4%)
User Interaction
None0 (0.0%)
Unknown147 (97.4%)
Required4 (2.6%)
Privileges Required
Low1 (0.7%)
High0 (0.0%)
None3 (2.0%)
Unknown147 (97.4%)

Top CVEs

Signals from CVEs in this product scope (151 CVEs).

151 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges to execute arbitrary SQL via t
Aug 18, 200410.031NONO
CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which caus
Jan 31, 200210.030NONO
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files vi
Oct 3, 20087.129NOYES
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi,
Jun 27, 20017.529NOYES
A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.
Apr 29, 20198.827NONO
Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" o
Aug 18, 200410.027NONO
SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to execute arbitrary SQL via the produ
Aug 18, 200410.025NONO
Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows
Sep 14, 20157.524NONO
Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not properly generate random values for c
Jan 28, 20117.524NONO
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descr
Aug 18, 20047.524NONO

Exploit Exposure

Signals from CVEs in this product scope (151 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (151 CVEs).

Media Mentions

Signals from CVEs in this product scope (151 CVEs).

Top CNAs Publishing CVEs For Bugzilla

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.0.216.11.5%00
5.0.134.81.6%00
5.045.71.8%00
4.5.626.31.8%00
4.5.555.21.8%00
4.5.465.01.6%00
4.5.365.01.6%00
4.5.274.91.6%00
4.5.174.91.6%00
4.564.71.6%00
4.4.945.52.1%00
4.4.845.52.1%00
4.4.745.52.1%00
4.4.655.72.1%00
4.4.585.22.0%00
4.4.495.11.8%00
4.4.395.11.8%00
4.4.2105.01.8%00
4.4.1116.11.5%00
4.4.1034.81.6%00