← Vulnerability feed

Vulnerability record · CVE-2015-4499 · published 14 September 2015

CVE-2015-4499: Mozilla bugzilla improper input validation vulnerability

Mozilla · Bugzilla

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.

7.5 CVSS 2.0 High EPSS 3.4% · top 11.7% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-4499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-1042Mozilla bugzilla vulnerabilitySQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to exec…EPSS 2.6%10.0CVE-2003-1043Mozilla bugzilla vulnerabilitySQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges…EPSS 2.6%10.0CVE-2004-0769Mozilla bugzilla vulnerabilityBuffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as original…EPSS 7.1%10.0CVE-2002-0007Mozilla bugzilla vulnerabilityCGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not…EPSS 2.4%8.8CVE-2018-5123Mozilla bugzilla cross-site request forgery vulnerabilityA third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al…EPSS 0.50%7.5CVE-2010-4568Mozilla bugzilla permissions and access controls vulnerabilityBugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not proper…EPSS 2.5%7.5CVE-2009-3125Mozilla bugzilla sql injection vulnerabilitySQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitr…EPSS 1.4%7.5CVE-2009-3165Mozilla bugzilla sql injection vulnerabilitySQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allo…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2015-4499), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.