fkie_cve-2014-1572
Vulnerability from fkie_nvd
Published
2014-10-13 01:55
Modified
2025-04-12 10:46
Severity ?
Summary
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.
References
security@mozilla.orghttp://advisories.mageia.org/MGASA-2014-0412.html
security@mozilla.orghttp://blog.gerv.net/2014/10/new-class-of-vulnerability-in-perl-web-applications/
security@mozilla.orghttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.html
security@mozilla.orghttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.html
security@mozilla.orghttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.html
security@mozilla.orghttp://openwall.com/lists/oss-security/2014/10/07/20
security@mozilla.orghttp://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.html
security@mozilla.orghttp://www.bugzilla.org/security/4.0.14/Vendor Advisory
security@mozilla.orghttp://www.mandriva.com/security/advisories?name=MDVSA-2014:200
security@mozilla.orghttp://www.opennet.ru/opennews/art.shtml?num=40766
security@mozilla.orghttp://www.reddit.com/r/netsec/comments/2ihen0/new_class_of_vulnerability_in_perl_web/
security@mozilla.orghttp://www.securitytracker.com/id/1030978
security@mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=1074812Patch
security@mozilla.orghttps://security.gentoo.org/glsa/201607-11
af854a3a-2127-422b-91ae-364da2661108http://advisories.mageia.org/MGASA-2014-0412.html
af854a3a-2127-422b-91ae-364da2661108http://blog.gerv.net/2014/10/new-class-of-vulnerability-in-perl-web-applications/
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.html
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.html
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.html
af854a3a-2127-422b-91ae-364da2661108http://openwall.com/lists/oss-security/2014/10/07/20
af854a3a-2127-422b-91ae-364da2661108http://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.html
af854a3a-2127-422b-91ae-364da2661108http://www.bugzilla.org/security/4.0.14/Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108http://www.mandriva.com/security/advisories?name=MDVSA-2014:200
af854a3a-2127-422b-91ae-364da2661108http://www.opennet.ru/opennews/art.shtml?num=40766
af854a3a-2127-422b-91ae-364da2661108http://www.reddit.com/r/netsec/comments/2ihen0/new_class_of_vulnerability_in_perl_web/
af854a3a-2127-422b-91ae-364da2661108http://www.securitytracker.com/id/1030978
af854a3a-2127-422b-91ae-364da2661108https://bugzilla.mozilla.org/show_bug.cgi?id=1074812Patch
af854a3a-2127-422b-91ae-364da2661108https://security.gentoo.org/glsa/201607-11
Impacted products
Vendor Product Version
fedoraproject fedora 19
fedoraproject fedora 20
fedoraproject fedora 21
mozilla bugzilla 2.0
mozilla bugzilla 2.2
mozilla bugzilla 2.4
mozilla bugzilla 2.6
mozilla bugzilla 2.8
mozilla bugzilla 2.9
mozilla bugzilla 2.10
mozilla bugzilla 2.12
mozilla bugzilla 2.14
mozilla bugzilla 2.14.1
mozilla bugzilla 2.14.2
mozilla bugzilla 2.14.3
mozilla bugzilla 2.14.4
mozilla bugzilla 2.14.5
mozilla bugzilla 2.16
mozilla bugzilla 2.16
mozilla bugzilla 2.16
mozilla bugzilla 2.16.1
mozilla bugzilla 2.16.2
mozilla bugzilla 2.16.3
mozilla bugzilla 2.16.4
mozilla bugzilla 2.16.5
mozilla bugzilla 2.16.6
mozilla bugzilla 2.16.7
mozilla bugzilla 2.16.8
mozilla bugzilla 2.16.9
mozilla bugzilla 2.16.10
mozilla bugzilla 2.16.11
mozilla bugzilla 2.16_rc2
mozilla bugzilla 2.17
mozilla bugzilla 2.17.1
mozilla bugzilla 2.17.2
mozilla bugzilla 2.17.3
mozilla bugzilla 2.17.4
mozilla bugzilla 2.17.5
mozilla bugzilla 2.17.6
mozilla bugzilla 2.17.7
mozilla bugzilla 2.18
mozilla bugzilla 2.18
mozilla bugzilla 2.18
mozilla bugzilla 2.18
mozilla bugzilla 2.18.1
mozilla bugzilla 2.18.2
mozilla bugzilla 2.18.3
mozilla bugzilla 2.18.4
mozilla bugzilla 2.18.5
mozilla bugzilla 2.18.6
mozilla bugzilla 2.18.6\+
mozilla bugzilla 2.18.7
mozilla bugzilla 2.18.8
mozilla bugzilla 2.18.9
mozilla bugzilla 2.19
mozilla bugzilla 2.19.1
mozilla bugzilla 2.19.2
mozilla bugzilla 2.19.3
mozilla bugzilla 2.20
mozilla bugzilla 2.20
mozilla bugzilla 2.20
mozilla bugzilla 2.20.1
mozilla bugzilla 2.20.2
mozilla bugzilla 2.20.3
mozilla bugzilla 2.20.4
mozilla bugzilla 2.20.5
mozilla bugzilla 2.20.6
mozilla bugzilla 2.20.7
mozilla bugzilla 2.21
mozilla bugzilla 2.21.1
mozilla bugzilla 2.21.2
mozilla bugzilla 2.21.2
mozilla bugzilla 2.22
mozilla bugzilla 2.22
mozilla bugzilla 2.22.1
mozilla bugzilla 2.22.2
mozilla bugzilla 2.22.3
mozilla bugzilla 2.22.4
mozilla bugzilla 2.22.5
mozilla bugzilla 2.22.6
mozilla bugzilla 2.22.7
mozilla bugzilla 2.23
mozilla bugzilla 2.23.1
mozilla bugzilla 2.23.2
mozilla bugzilla 2.23.3
mozilla bugzilla 2.23.4
mozilla bugzilla 3.0
mozilla bugzilla 3.0
mozilla bugzilla 3.0.0
mozilla bugzilla 3.0.1
mozilla bugzilla 3.0.2
mozilla bugzilla 3.0.3
mozilla bugzilla 3.0.4
mozilla bugzilla 3.0.5
mozilla bugzilla 3.0.6
mozilla bugzilla 3.0.7
mozilla bugzilla 3.0.8
mozilla bugzilla 3.0.9
mozilla bugzilla 3.0.10
mozilla bugzilla 3.0.11
mozilla bugzilla 3.0_rc1
mozilla bugzilla 3.1.0
mozilla bugzilla 3.1.1
mozilla bugzilla 3.1.2
mozilla bugzilla 3.1.3
mozilla bugzilla 3.1.4
mozilla bugzilla 3.2
mozilla bugzilla 3.2
mozilla bugzilla 3.2
mozilla bugzilla 3.2.1
mozilla bugzilla 3.2.2
mozilla bugzilla 3.2.3
mozilla bugzilla 3.2.4
mozilla bugzilla 3.2.5
mozilla bugzilla 3.2.6
mozilla bugzilla 3.2.7
mozilla bugzilla 3.2.8
mozilla bugzilla 3.2.9
mozilla bugzilla 3.2.10
mozilla bugzilla 3.3
mozilla bugzilla 3.3.1
mozilla bugzilla 3.3.2
mozilla bugzilla 3.3.3
mozilla bugzilla 3.3.4
mozilla bugzilla 3.4
mozilla bugzilla 3.4
mozilla bugzilla 3.4.1
mozilla bugzilla 3.4.2
mozilla bugzilla 3.4.3
mozilla bugzilla 3.4.4
mozilla bugzilla 3.4.5
mozilla bugzilla 3.4.6
mozilla bugzilla 3.4.7
mozilla bugzilla 3.4.8
mozilla bugzilla 3.4.9
mozilla bugzilla 3.4.10
mozilla bugzilla 3.4.11
mozilla bugzilla 3.4.12
mozilla bugzilla 3.4.13
mozilla bugzilla 3.5
mozilla bugzilla 3.5.1
mozilla bugzilla 3.5.2
mozilla bugzilla 3.5.3
mozilla bugzilla 3.6
mozilla bugzilla 3.6
mozilla bugzilla 3.6.0
mozilla bugzilla 3.6.1
mozilla bugzilla 3.6.2
mozilla bugzilla 3.6.3
mozilla bugzilla 3.6.4
mozilla bugzilla 3.6.5
mozilla bugzilla 3.6.6
mozilla bugzilla 3.6.7
mozilla bugzilla 3.6.8
mozilla bugzilla 3.6.9
mozilla bugzilla 3.6.10
mozilla bugzilla 3.6.11
mozilla bugzilla 3.6.12
mozilla bugzilla 3.6.13
mozilla bugzilla 3.7
mozilla bugzilla 3.7.1
mozilla bugzilla 3.7.2
mozilla bugzilla 3.7.3
mozilla bugzilla 4.0
mozilla bugzilla 4.0
mozilla bugzilla 4.0
mozilla bugzilla 4.0.1
mozilla bugzilla 4.0.10
mozilla bugzilla 4.0.11
mozilla bugzilla 4.0.12
mozilla bugzilla 4.0.13
mozilla bugzilla 4.0.14
mozilla bugzilla 4.1
mozilla bugzilla 4.1.1
mozilla bugzilla 4.1.2
mozilla bugzilla 4.1.3
mozilla bugzilla 4.2
mozilla bugzilla 4.2
mozilla bugzilla 4.2
mozilla bugzilla 4.2.1
mozilla bugzilla 4.2.2
mozilla bugzilla 4.2.3
mozilla bugzilla 4.2.4
mozilla bugzilla 4.2.5
mozilla bugzilla 4.2.6
mozilla bugzilla 4.2.7
mozilla bugzilla 4.2.8
mozilla bugzilla 4.2.9
mozilla bugzilla 4.2.10
mozilla bugzilla 4.3
mozilla bugzilla 4.3.1
mozilla bugzilla 4.3.2
mozilla bugzilla 4.3.3
mozilla bugzilla 4.4
mozilla bugzilla 4.4
mozilla bugzilla 4.4
mozilla bugzilla 4.4.1
mozilla bugzilla 4.4.2
mozilla bugzilla 4.4.3
mozilla bugzilla 4.4.4
mozilla bugzilla 4.4.5
mozilla bugzilla 4.5
mozilla bugzilla 4.5.1
mozilla bugzilla 4.5.2
mozilla bugzilla 4.5.3
mozilla bugzilla 4.5.4
mozilla bugzilla 4.5.5



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*",
              "matchCriteriaId": "5991814D-CA77-4C25-90D2-DB542B17E0AD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*",
              "matchCriteriaId": "FF47C9F0-D8DA-4B55-89EB-9B2C9383ADB9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*",
              "matchCriteriaId": "56BDB5A0-0839-4A20-A003-B8CD56F48171",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "DC38A53F-60E6-4F7A-A953-C53D141E830D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "DAFEF951-3FE8-49DD-B3DD-E526D5B52998",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "8112FF13-B4CE-4DC7-85B1-C69D975F162B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "86F5A3CA-E4A6-4E51-AC83-0C8F3E5E2C4E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "F6E5E379-D475-42F3-B0DC-3D04C1D25566",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "A3B3EF74-4784-47A7-8994-21EF489F4008",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "893741D3-062B-45F9-B5A3-1B81058E7FD7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "E8D53B5F-6AEE-4192-B838-E1DA92C59285",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "1883A98C-E595-4F3C-87BF-A63393F9F561",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "DD49E53A-5676-4FAC-A8A2-30FAC04C33D7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "1084AF8E-5269-4EFF-BBD2-C5A77945FCF2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "D9A4B035-B73E-48E9-BBB9-83219F5D2A95",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "9452C271-2812-4775-8396-394C642EACFD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.14.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "2D351AF2-C0AB-4BB3-8692-677A3025A615",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16:*:*:*:*:*:*:*",
              "matchCriteriaId": "F16D338E-C5BC-46E1-95DD-D9B0E25EE56E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "5877CECA-F758-4F48-B4F4-2C4C1DF01FA0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "D63CE086-5872-4594-8F4B-8D812E7EF09C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "19F19219-3AFD-4D8E-B02B-BFCBD1BC7C36",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "B900D9A7-913A-4176-90CF-C7C3B09A4261",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "B692910E-633D-4A88-B245-56A2B58DD4CB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "F86EE5DB-442B-4C78-8152-AF1048C6A974",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "19B82A1A-56EB-41D5-8619-2A717E3A6ECF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "83A0406C-AAF2-4A4C-9567-E21DF1B6C46E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "64434BFC-DDC0-4C7D-B578-472B0610C89E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "A30F28D9-B000-4C26-A911-5E1B8A867BF6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A123F78-A671-4FB5-AE78-83762E9323C7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "28C34288-A326-4B71-99B0-DA9FFD28160F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "73648879-BB08-4BE4-A7FF-1E8DF4E264B4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.16_rc2:*:*:*:*:*:*:*",
              "matchCriteriaId": "1B4CC7E4-617D-498E-A367-374478158FA5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "9B2FC5C7-B218-4B87-9805-F90AC0E7A281",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "BBCDA64F-C49A-4F5B-B285-4079D8E3A499",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "930AF809-CA52-41CB-985A-066B8239C7CD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "85ED3457-CC21-4DB3-931F-677F723E1B2A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C8711D3-55CF-4131-BBAC-6BE07068219F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "DF54FFA5-5177-46E6-9AFA-BA3345C16E8A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "69D7EA7C-B401-4F5A-AC08-2199DD117403",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.17.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "DC2DDC7C-CD2B-4597-A5E0-266A884958FC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18:*:*:*:*:*:*:*",
              "matchCriteriaId": "DDB99B2D-CA05-4BC0-BCA4-9B94DF248333",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "3635C0E9-2E43-4BAE-8267-2BB2F68B03BD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "4869A709-AF79-49BD-A7D2-D48A8D79A085",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18:rc3:*:*:*:*:*:*",
              "matchCriteriaId": "EAC72143-27C3-498F-AFAB-98AE043C0545",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "BE5E8E72-D493-460D-B5A0-F90C291398A5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "04885D31-09F3-455F-A1A9-815E182ABCF9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F153300E-42CC-4BDD-88EC-E8A0ADB4E3B7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "92BCD546-2A50-4F43-935C-B68459EE894E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "C535BAB7-6146-440B-ADBD-51007585CFC8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "7B6BA7E8-DEC7-4D94-B9F9-B70EC39FD892",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.6\\+:*:*:*:*:*:*:*",
              "matchCriteriaId": "15E6F17A-7292-4640-A5E6-59865D1CDD7B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "E9130B6B-764B-4B83-A2BD-E16013682875",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "7C7A5111-8729-48DF-B308-7A489BEFA6D0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.18.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "15E24C39-0E61-4A57-B93F-F0ABF4CEAEEB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "725BD7BE-1769-4032-ADA8-9ED15528C770",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.19.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "239D70F4-7D86-4A57-ACEF-440F68994FB6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.19.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "ABEE2C94-DA69-4A78-A15F-538383A7460E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "4F7CD64E-7FAA-40DC-B36E-8B7EB9D620FB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "A749C7AB-6F60-469C-BD95-759205DDA345",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "B45F6C27-D89A-42A0-A304-5B0C57D2A9F1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "196B7CD8-D721-4CFB-B126-78758128E900",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "BEA9DE63-9951-4FE0-80BE-0F6F197303D7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0CEDD02-1CB8-4D5B-B82B-E300B4E39065",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "8E27101B-7985-4412-A14F-9ED11E4C874C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "8A74E8A2-223E-4877-989E-494362B513E9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "E0CAFB45-B115-4492-9919-60223304BB27",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "DC3F7C44-C734-419B-AB62-3AD52554FC7D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.20.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "695036D1-994C-451E-8D53-0A345702E4D1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*",
              "matchCriteriaId": "2053CFB4-602E-4141-BB3D-A440E2A31D85",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "31ACBA13-AC13-4469-862F-B3DD2327B6FC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "9E9EC243-3E25-4234-A88A-FDD5B594BFBA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.21.2:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "AE0570E9-B967-4325-92CB-2FB6CA010C4F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22:*:*:*:*:*:*:*",
              "matchCriteriaId": "F2969731-8256-431B-9356-4BC873D98F6D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "1C166E42-9B36-4883-B738-EEBEF3056D98",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "E5177876-0FEC-481B-815F-84AF53968644",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "BC38566A-07F1-4F21-BAC1-259F844DC15C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "AE1684B8-3060-4139-BC06-707F27A05958",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "FF32C74C-3EA3-4E1F-BADA-BB4A92068266",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "D569A750-C649-4D40-89AB-D29773E66F66",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "95B69FA8-1182-46F1-952F-4610288ED409",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.22.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "5716BB97-7829-4FDE-92AC-69CA10332F45",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.23:*:*:*:*:*:*:*",
              "matchCriteriaId": "02846865-D124-4C72-85C8-59A7C6F43E2E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.23.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "99B59422-ED6E-4F82-8D0C-091058D1C438",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.23.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F658844A-6253-4A18-8A5D-1E818BE7A367",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.23.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "4753AB35-B95C-4544-A874-5E6D83929AC1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:2.23.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "C4880D54-CA42-4CCA-B01E-2C125002BF5C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "D4D9F54A-15A7-4899-B695-D9D8B96C4A9B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "BD56D9C0-38C6-4679-8104-1A0B88B71C0E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "45C36666-518F-4956-816A-940930425955",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "FF2DF96F-E45E-45AF-85E5-E939F923EC1B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "80EBAA09-F2C8-445E-8E3A-B5F937E1B1E2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "11C6713F-01ED-4AE9-AE42-89926067E6E6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "7AB5010D-37A3-4B6E-92B6-6F41A3708851",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "EEB09719-122F-4D25-B680-18029D5D9DE9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "AF585D92-9FAF-4858-A956-68AF77227333",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "7BA67823-C9D9-4C5B-A4ED-669E6F1851C0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "CB0F7531-A660-4604-80BD-15B01E2916BD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "A6FE6868-BB9F-4EB8-9E37-3438559CB01B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "1EC90352-C94A-4F47-AFB7-713B547373CC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "E5E77E01-D779-482A-9FAC-4AC210B68771",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.0_rc1:*:*:*:*:*:*:*",
              "matchCriteriaId": "5E608E27-D43C-4F34-952D-2F49A71B1E2B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "154EA18F-534C-4095-837D-BB9865D25F23",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "585F05F2-B294-4218-9209-C487B4D2994B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F3246890-8D66-474F-AC9C-BC556426467D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "7090332F-4CC2-4ADD-AEEC-75238BCA55CC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.1.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "F960BE59-05B1-4438-A854-279612E13A7B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F248EA4D-1A39-40FD-8D3C-9701D36FD6B1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "170EB43B-9488-4E25-9401-B84DE838247B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "B1ED7682-A315-4F92-9F9F-38290BCC058E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "14B5A433-526F-436E-9FCD-B71E661180FD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "48EDC5BC-AD4B-4E67-B79C-F44292307AB4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "6FEC62B7-2CAA-4A0D-A9B2-B4A6B105A6F7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "4B4A7A67-1355-4648-B8C9-3231BED96547",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "442AB3EE-61DF-4B25-ABEB-55905C01E376",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "7F825E34-D529-4ADC-A7D6-1BD9DAE86FC1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "C1F92D0C-AF71-4FD3-BC4B-C6D0F1F84F9B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "CBC26020-BFD7-493B-BDE2-1EC8DEA1A6DA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "984463B4-00A8-423B-B0C5-A7C4FECF064C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C7DC534-FF77-414C-A1DC-945F508CC3C9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "BEB4EF1D-D4D0-40DA-BE78-24FD48030EE0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "B2962084-F778-4574-8105-8C5A260CCBD7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.3.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "FF288A74-070E-4EB4-BB92-7D4D41635DD1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.3.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B8B31F0-6FCC-4258-865B-B65ECBFAF252",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.3.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "7A0CCF96-777F-4CEE-BC04-2974663CF5E7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "D6A71919-DC70-4AE2-9D16-76A177DAE331",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "780896D3-3B49-486F-A136-D3D175C00A34",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "EA43E47B-F474-4F5B-A91B-9AF99359FE5F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "A7A3A453-EE50-458C-8F31-D7AA232006FC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "3D920D39-683D-4F9F-AA85-3C4D1600DAD6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "E7A4F1FD-2B00-4A99-AAA1-DBBFE3748D87",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "EF6A3C0F-8778-4236-B4DC-41DBCF43EB62",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "7D134D4D-6A95-48FE-B8E5-4F90692CB4FD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "08C34E6F-8233-4575-AAE7-4DBFC27453F8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "6D8155F8-CAB1-4EED-B576-F4102253BD25",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "593D2F3B-A386-48D8-BF19-A12F1B4962A6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "F37C651D-8989-478B-A991-654FCDEC8B1D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "AE170AE5-37F5-4750-ACD9-13CA691A80C5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "1DE75B2F-A183-4ED9-A9E9-7ADF54C341FF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.4.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "A4D7380C-5608-4F96-82E3-4B36CDCD71EC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "850ADB66-21F2-49CB-B105-BDA16A286CFC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "1907D4D0-9D6E-476E-BD1A-88A32D3EFE38",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.5.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "61DD0779-786E-4714-AA73-86FB19E26028",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.5.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "A8E8DD97-5799-465D-8B99-F2BD6AA681AB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "03E40C09-0696-45BC-9AE8-9F6F20964600",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "397E07B5-3D9D-44C7-B8B3-18D04EE84405",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A1AD503-7F78-4597-AECD-6DC530AD4D3C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "BCAD5285-E485-4F49-99CF-287545260FDD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "5C193DF3-8D23-44A9-94DE-9F4F7358ED3F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "80BA8C84-32C3-4ECF-B4C7-573B12441D22",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "820EC9F1-B66C-43CE-B254-145F4AC23083",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "C4BDA6DC-8D53-417D-8320-CE266F8607B7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B01E0D5-3F26-4A71-A22C-FAD7CBF47283",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "6C33D8DA-86A4-4A70-82F8-27D5DE3881EA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "884D0728-8E3C-47F3-9DDD-FA976E1553EB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "C47C594A-D3B6-44FD-93D7-7E69212050BF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "551303CA-63C5-4A3A-9280-ADB2B77C05F7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "0777EB93-D11C-4837-BB7F-96DEC716E1BB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "10FFAD30-56A0-40C8-AE70-70DD9904C528",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.6.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "3620DE78-AF48-44EC-B211-E0C26F4E951F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "2757B2A7-5232-4245-9CC6-91BF9E3ECA09",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.7.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "740ADCB7-B296-4728-A73A-9691265B8F07",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.7.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "6187C92D-FEE9-4B1B-B7ED-9A1DD360B204",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:3.7.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "71213AF6-48CC-469F-9FBA-CAF1D3237657",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "DABC1683-0E04-456E-9500-68D0D35815E6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "38D71912-DCD6-44BB-8A86-72D207B49E58",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "D5A8816A-84EE-44B0-AD3B-5C9BC9B3E71E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "A367BFF0-397D-416F-960C-602E8B66421A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "145D0FF7-1691-4A73-95FA-284A9EF79F65",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "A9C9A0A8-139B-469D-ABE8-2724D65F7EAA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A54C2C7-AA44-46E9-BF03-E00018084093",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "BECED922-3748-4534-9750-3A061B939A0B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.0.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "A8A5E5C6-AF2D-4C31-B422-63D0182EC21B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "85CDC579-6967-4E5C-B716-B2BC04F6DBF2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "27783033-F558-427C-89A7-C3638C57F2A0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "E91557C7-8C53-49C4-8BC5-7F86D4AA09B8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "50448355-F1D3-48AB-AED0-5FE027D7C199",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "7CE9B4E3-8044-4305-A517-E695D0831355",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "4BDA28D1-5B26-4FBA-B685-C230569AF024",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "F61B90BF-3548-4D3A-BF70-A9DC96C11775",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "AD204F45-15FE-4677-BC4C-A53F322A3B15",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "22FAFCDF-C615-4958-9C6D-E74EC11E9A62",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "4D623AEB-622E-470E-898C-A447F9C4066A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "9019921A-B8D2-4774-AB6B-673FC2FD2197",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "1DC1A059-DDE4-4442-BD90-20AB3CE0E1CC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "4801DB4A-F828-4E95-8619-F909D5D39524",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "1E0D48CD-C77A-4D86-B091-2B8DF3ADA6D7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "956C5C97-E7A8-49F2-8AC6-9570A5948395",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "281A3D1A-1F92-454D-AE09-522114FF9D8D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "717B879A-EDEA-4917-A75E-2C40BB8D35D7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "F119CA93-4D32-4852-90AD-A23215D6CBAC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "6CA9A1C4-412D-4EED-8259-04F48322238B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.3.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "27847E43-22AD-468D-8E64-8D56EA8CBE50",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.3.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "8DBB66FA-6E99-4F08-A223-6070E193B869",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "D00AE646-61CC-4036-8B8F-35B818530BFC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "FF326273-99CF-40C3-B112-F5F18C94978F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "ECED66BE-C877-4250-AC7A-FAEAD9DAAC31",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "9FFFD96D-D0B5-47BB-91D9-3736E343711E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "4D710732-6D93-4143-874F-81B19F70FBEF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "FD56846F-40B5-4A45-99DB-44C56E3A20A3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "32C22A06-5F01-4C6A-886F-E3C0776C3C5B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.4.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "6457398E-A1C9-4F72-BBF7-FC54118FA91C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "5FA8C43E-AD0C-45F7-BC20-61358C7F23EA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.5.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "E86608A6-8B14-4D27-A86B-1DD10E1F7825",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.5.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "D7F176CD-2EE5-4C7D-A376-4EA8918610C3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.5.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "0BD5F23A-33EC-4D8A-B39D-972A048DAB0A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.5.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "D1F3C39E-50A1-4005-AC0B-097A1FA6E1C2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mozilla:bugzilla:4.5.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "47A322B9-DA3A-448C-BD61-3E67A98AC74E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted."
    },
    {
      "lang": "es",
      "value": "La funci\u00f3n confirm_create_account en la caracteristica account-creation en token.cgi en Bugzilla 2.x hasta 4.0.x anterior a 4.0.15, 4.1.x y 4.2.x anterior a 4.2.11, 4.3.x y 4.4.x anterior a 4.4.6, y 4.5.x anterior a 4.5.6 no especifica un contexto escalar para el par\u00e1metro realname, lo que permite a atacantes remotos crear cuentas con direcciones de e-mail no verificadas mediante el env\u00edo de tres valores realname con realname=login_name como el segundo, tal y como fue demostrado mediante la selecci\u00f3n de una direcci\u00f3n de e-mail con un nombre de dominio para el cual privilegios de grupo se ceden autom\u00e1ticamente."
    }
  ],
  "id": "CVE-2014-1572",
  "lastModified": "2025-04-12T10:46:40.837",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "NONE",
          "baseScore": 5.0,
          "confidentialityImpact": "NONE",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 2.9,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2014-10-13T01:55:06.933",
  "references": [
    {
      "source": "security@mozilla.org",
      "url": "http://advisories.mageia.org/MGASA-2014-0412.html"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://blog.gerv.net/2014/10/new-class-of-vulnerability-in-perl-web-applications/"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.html"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.html"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.html"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://openwall.com/lists/oss-security/2014/10/07/20"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.html"
    },
    {
      "source": "security@mozilla.org",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.bugzilla.org/security/4.0.14/"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:200"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://www.opennet.ru/opennews/art.shtml?num=40766"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://www.reddit.com/r/netsec/comments/2ihen0/new_class_of_vulnerability_in_perl_web/"
    },
    {
      "source": "security@mozilla.org",
      "url": "http://www.securitytracker.com/id/1030978"
    },
    {
      "source": "security@mozilla.org",
      "tags": [
        "Patch"
      ],
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1074812"
    },
    {
      "source": "security@mozilla.org",
      "url": "https://security.gentoo.org/glsa/201607-11"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://advisories.mageia.org/MGASA-2014-0412.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://blog.gerv.net/2014/10/new-class-of-vulnerability-in-perl-web-applications/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://openwall.com/lists/oss-security/2014/10/07/20"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://www.bugzilla.org/security/4.0.14/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2014:200"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.opennet.ru/opennews/art.shtml?num=40766"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.reddit.com/r/netsec/comments/2ihen0/new_class_of_vulnerability_in_perl_web/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securitytracker.com/id/1030978"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1074812"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://security.gentoo.org/glsa/201607-11"
    }
  ],
  "sourceIdentifier": "security@mozilla.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…