← Vulnerability feed

Vulnerability record · CVE-2008-2105 · published 7 May 2008

CVE-2008-2105: Mozilla bugzilla permissions and access controls vulnerability

Mozilla · Bugzilla

email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

3.5 CVSS 2.0 Low EPSS 0.97% · top 39.6% CWE-264 · Permissions and access controls
3.5CVSS 2.0 base score
0.97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

AV:N/AC:M/Au:S/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2105 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-1043Mozilla bugzilla vulnerabilitySQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges…EPSS 2.6%10.0CVE-2004-0769Mozilla bugzilla vulnerabilityBuffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as original…EPSS 7.1%10.0CVE-2003-1042Mozilla bugzilla vulnerabilitySQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to exec…EPSS 2.6%10.0CVE-2002-0007Mozilla bugzilla vulnerabilityCGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not…EPSS 2.4%8.8CVE-2018-5123Mozilla bugzilla cross-site request forgery vulnerabilityA third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al…EPSS 0.50%7.5CVE-2015-4499Mozilla bugzilla improper input validation vulnerabilityUtil.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during acco…EPSS 3.4%7.5CVE-2010-4568Mozilla bugzilla permissions and access controls vulnerabilityBugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not proper…EPSS 2.5%7.5CVE-2009-3125Mozilla bugzilla sql injection vulnerabilitySQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitr…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2008-2105), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.