CVE-2014-8630
CVE-2014-8630 is a medium-severity vulnerability in Mozilla Bugzilla with a CVSS 2.0 base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-77.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.5)
- EPSS exploit prediction: 2% (80th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-77
- Affected product: Mozilla Bugzilla
- Published:
- Last modified:
Description
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
Frequently asked questions
- What is CVE-2014-8630?
- Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
- How severe is CVE-2014-8630?
- CVE-2014-8630 has a CVSS 2.0 base score of 6.5, rated medium severity.
- Is CVE-2014-8630 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (80th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-8630?
- CVE-2014-8630 primarily affects Mozilla Bugzilla. In total, 41 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2014-8630?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2014-8630 published?
- CVE-2014-8630 was published on 2015-02-01 and last updated on 2026-06-17.
References
- http://advisories.mageia.org/MGASA-2015-0048.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/149921.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-February/149925.html
- http://www.bugzilla.org/security/4.0.15/
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:030
- https://bugzilla.mozilla.org/show_bug.cgi?id=1079065
- https://security.gentoo.org/glsa/201607-11
Affected products (41)
- cpe:2.3:a:mozilla:bugzilla:*:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:4.5.6:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
More vulnerabilities in Mozilla Bugzilla
- CVE-2004-0769 — Critical (CVSS 10.0): Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers…
- CVE-2003-1043 — Critical (CVSS 10.0): SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated…
- CVE-2003-1042 — Critical (CVSS 10.0): SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with…
- CVE-2002-0007 — Critical (CVSS 10.0): CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP…
- CVE-2018-5123 — High (CVSS 8.8): A third party website can access information available to a user with access to a restricted bug entry using the image…
- CVE-2015-4499 — High (CVSS 7.5): Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles…
All CVEs affecting Mozilla Bugzilla →
Other CWE-77 (Command Injection) vulnerabilities
- CVE-2026-105484 — Critical (CVSS 10.0): A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the…
- CVE-2026-105134 — Critical (CVSS 10.0): A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file…
- CVE-2026-102240 — Critical (CVSS 10.0): A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file…
- CVE-2026-101076 — Critical (CVSS 10.0): A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file…
- CVE-2026-101075 — Critical (CVSS 10.0): A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of…
- CVE-2026-101072 — Critical (CVSS 10.0): A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file…