CVE-2013-0786: Mozilla Bugzilla

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.

Affected products

  • Mozilla Bugzilla: up to and including 3.6.12; version 3.6 only; version 3.6.0 only; version 3.6.1 only; version 3.6.2 only; version 3.6.3 only; …

Published 2013-02-24. Last modified 2026-06-16.