Candidate: CVE-2010-3764 PublicDate: 2010-11-05 17:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3764 Description: The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_bugzilla: upstream_bugzilla: released (3.2.9, 3.4.9, 3.6.3) dapper_bugzilla: ignored (reached end-of-life) hardy_bugzilla: ignored (reached end-of-life) karmic_bugzilla: ignored (reached end-of-life) lucid_bugzilla: ignored (reached end-of-life) maverick_bugzilla: ignored (reached end-of-life) natty_bugzilla: not-affected (3.6.3.0-1) oneiric_bugzilla: not-affected (3.6.3.0-1) precise_bugzilla: DNE (dropped by debian) quantal_bugzilla: DNE (dropped by debian) raring_bugzilla: DNE (dropped by debian) saucy_bugzilla: DNE (dropped by debian) devel_bugzilla: DNE (dropped by debian)