← Back

CVE-2014-8630

nvd nist
Published: Feb 1, 2015Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.

Affected (41)

1 product
Bugzilla
1 product
Fedora
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 4.0.16
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1
Version 4.2.10
Version 4.2.11
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 4.2.6
Version 4.2.7
Version 4.2.8
Version 4.2.9
Version 4.2
Version 4.2 rc1
Version 4.2 rc2
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3
Version 4.4.1
Version 4.4.2
Version 4.4.3
Version 4.4.4
Version 4.4.5
Version 4.4.6
Version 4.4
Version 4.4 rc1
Version 4.4 rc2
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.5.4
Version 4.5.5
Version 4.5.6
Version 4.5
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 20
Version 21

References (14)

Source: security@mozilla.org
Issue TrackingPatchVendor Advisory
Source: security@mozilla.org
Issue TrackingVendor Advisory
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.