← Vulnerability feed

Vulnerability record · CVE-2015-8509 · published 3 January 2016

CVE-2015-8509: Mozilla bugzilla information exposure vulnerability

Mozilla · Bugzilla

Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.

3.5 CVSS 3.0 Low EPSS 1.9% · top 21.1% CWE-200 · Information exposure
3.5CVSS 3.0 base score, v2 4.3
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that interprets CSV data as JavaScript code.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-8509 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-1042Mozilla bugzilla vulnerabilitySQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to exec…EPSS 2.6%10.0CVE-2003-1043Mozilla bugzilla vulnerabilitySQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges…EPSS 2.6%10.0CVE-2004-0769Mozilla bugzilla vulnerabilityBuffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as original…EPSS 7.1%10.0CVE-2002-0007Mozilla bugzilla vulnerabilityCGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not…EPSS 2.4%8.8CVE-2018-5123Mozilla bugzilla cross-site request forgery vulnerabilityA third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al…EPSS 0.50%7.5CVE-2015-4499Mozilla bugzilla improper input validation vulnerabilityUtil.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during acco…EPSS 3.4%7.5CVE-2010-4568Mozilla bugzilla permissions and access controls vulnerabilityBugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not proper…EPSS 2.5%7.5CVE-2009-3125Mozilla bugzilla sql injection vulnerabilitySQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitr…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2015-8509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.