CVE Vulnerabilities

CVE-2001-1404

Published: Sep 10, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.4 (including)2.4 (including)
BugzillaMozilla2.6 (including)2.6 (including)
BugzillaMozilla2.8 (including)2.8 (including)
BugzillaMozilla2.10 (including)2.10 (including)
BugzillaMozilla2.12 (including)2.12 (including)
BugzillaMozilla2.14 (including)2.14 (including)
Red Hat Powertools 7.0RedHat*
Red Hat Powertools 7.1RedHat*

References