Unrated severityNVD Advisory· Published Oct 5, 2005· Updated Jun 16, 2026
CVE-2005-3139
CVE-2005-3139
Description
Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:mozilla:bugzilla:2.19.1:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:mozilla:bugzilla:2.19.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.19.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.19.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.21:*:*:*:*:*:*:*
- Range: 2.19.1 - 2.20rc2, 2.21
Patches
Vulnerability mechanics
References
5- secunia.com/advisories/17030/nvdPatchVendor Advisory
- www.bugzilla.org/security/2.18.4/nvdPatchVendor Advisory
- www.securityfocus.com/bid/14996nvdPatch
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42799nvd
News mentions
0No linked articles in our index yet.