CVE-2012-0448: Mozilla Bugzilla

Medium severity, CVSS 4.0. EPSS: 1% chance of exploitation in the next 30 days.

Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.

Affected products

  • Mozilla Bugzilla: version 2.0 only; version 2.2 only; version 2.4 only; version 2.6 only; version 2.8 only; version 2.9 only; …

Published 2012-02-02. Last modified 2026-06-16.