← Back

CVE-2009-0483

nvd nist
Published: Feb 9, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.

Affected (76)

Products: Mozilla: Bugzilla
1 product
Bugzilla
Configuration A
76 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 2.10
Version 2.12
Version 2.14.1
Version 2.14.2
Version 2.14.3
Version 2.14.4
Version 2.14.5
Version 2.14
Version 2.16.10
Version 2.16.11
Version 2.16.1
Version 2.16.2
Version 2.16.3
Version 2.16.4
Version 2.16.5
Version 2.16.6
Version 2.16.7
Version 2.16.8
Version 2.16.9
Version 2.16
Version 2.16 rc1
Version 2.16_rc2
Version 2.17.1
Version 2.17.2
Version 2.17.3
Version 2.17.4
Version 2.17.5
Version 2.17.6
Version 2.17.7
Version 2.17
Version 2.18.1
Version 2.18.2
Version 2.18.3
Version 2.18.4
Version 2.18.5
Version 2.18.6
Version 2.18.7
Version 2.18.8
Version 2.18.9
Version 2.18
Version 2.18 rc1
Version 2.18 rc2
Version 2.18 rc3
Version 2.19.1
Version 2.19.2
Version 2.19.3
Version 2.19
Version 2.20.1
Version 2.20.2
Version 2.20.3
Version 2.20.4
Version 2.20.5
Version 2.20.6
Version 2.20
Version 2.20 rc1
Version 2.20 rc2
Version 2.21.1
Version 2.21.2
Version 2.21
Version 2.22.1
Version 2.22.2
Version 2.22.3
Version 2.22.4
Version 2.22.5
Version 2.22.6
Version 2.22
Version 2.22 rc1
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.2
Version 3.3.1

Timeline

No history available yet.