aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Bumped to the correct date (v2)release-3.4.14bugzilla-3.4.14Dave Lawrence2012-01-311-1/+1
* Bumped to the correct dateDave Lawrence2012-01-311-1/+1
* Bumped version for 3.4.14Dave Lawrence2012-01-312-3/+3
* Bug 714472: (CVE-2012-0448) [SECURITY] utf8 homoglyphs are allowed in email a...Frédéric Buclin2012-01-314-7/+5
* Bug 720750: Release notes for Bugzilla 3.4.14Dave Lawrence2012-01-271-0/+6
* Bug 469068: SMTP parameters not documentedMatt Selsky2012-01-211-0/+62
* Bug 591638: In the admin page, the link to edit field values is named 'Field ...A. Shimono2012-01-111-1/+1
* Bug 319684: The documentation is unclear about how to disable quipsMatt Selsky2012-01-061-7/+12
* Bump the version number post-releaseDave Lawrence2011-12-291-1/+1
* Bump version number for 3.4.13release-3.4.13bugzilla-3.4.13Dave Lawrence2011-12-282-3/+3
* Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebSer...Frédéric Buclin2011-12-285-45/+51
* Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabula...Byron Jones2011-12-282-3/+3
* Bug 713343: Release notes for Bugzilla 3.4.13Frédéric Buclin2011-12-261-0/+6
* Bug 707170: Several features about custom fields are missing in the documenta...Frédéric Buclin2011-12-081-7/+40
* Bug 692354: Incorrect parameter type in WebServices documentation for Bug.add...Matt Selsky2011-12-051-1/+1
* Bug 591610: Custom field doc doesn't include 'Bug ID' typeFrédéric Buclin2011-12-021-0/+5
* Bug 531257: Wrong error codes in WebServices documentationMatt Selsky2011-11-161-2/+2
* Bug 445804: Suggested crontab configuration opens security holeMatt Selsky2011-10-151-3/+3
* Bump the version number post-release.Max Kanat-Alexander2011-08-051-1/+1
* Bump version number for 3.4.12.release-3.4.12bugzilla-3.4.12Max Kanat-Alexander2011-08-042-3/+3
* Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-m...Byron Jones2011-08-041-1/+1
* Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XS...Byron Jones2011-08-043-30/+104
* Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when creati...Frédéric Buclin2011-08-042-3/+3
* Bug 660053: (CVE-2011-2976) [SECURITY] If a BUGLIST cookie is compromised, it...Max Kanat-Alexander2011-08-043-19/+14
* Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment ...Frédéric Buclin2011-08-042-1/+4
* Bug 675751: Release notes for Bugzilla 3.4.12Frédéric Buclin2011-08-031-0/+6
* Bump the version number post-release.Max Kanat-Alexander2011-04-271-1/+1
* Bump version number for 3.4.11.release-3.4.11bugzilla-3.4.11Max Kanat-Alexander2011-04-272-3/+3
* Bug 653275 - Release Notes for Bugzilla 3.4.11Max Kanat-Alexander2011-04-271-0/+11
* Bug 646578: Remove the usage of Math::Random::Secure, as it is too difficultMax Kanat-Alexander2011-04-273-34/+11
* Bug 311392 - Typos and proper name of Red Hat's stuffMatt Selsky2011-03-222-10/+10
* Bug 586011 - Change references to 'DarwinPorts' to 'MacPorts' (proper project...David Lawrence2011-03-181-3/+3
* Bug 633422: Fix the documentation for User.get's include_disabled parameterMax Kanat-Alexander2011-02-131-0/+5
* Bump the version number post-release.Max Kanat-Alexander2011-01-241-1/+1
* Bump version number for 3.4.10.release-3.4.10bugzilla-3.4.10Max Kanat-Alexander2011-01-242-4/+4
* Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness ofMax Kanat-Alexander2011-01-244-5/+76
* Bug 621105 - [SECURITY] Voting lacks CSRF protectionDavid Lawrence2011-01-243-0/+6
* Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking f...Frédéric Buclin2011-01-243-8/+20
* Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injecti...Reed Loden2011-01-241-3/+3
* Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protectionFrédéric Buclin2011-01-242-2/+12
* Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protectionFrédéric Buclin2011-01-243-3/+13
* Bug 627930 - Release Notes for Bugzilla 3.4.10Max Kanat-Alexander2011-01-231-2/+10
* Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.p...Reed Loden2011-01-211-2/+2
* Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R ins...Frédéric Buclin2010-11-271-3/+7
* Bug 591165: (CVE-2010-2761) [SECURITY] Add CGI.pm v3.50 as an optional module...Reed Loden2010-11-101-0/+9
* Bump the version number post-release.Max Kanat-Alexander2010-11-021-1/+1
* Bump version number for 3.4.9.release-3.4.9bugzilla-3.4.9Max Kanat-Alexander2010-11-022-3/+3
* Bug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to non-ra...Byron Jones2010-11-031-1/+2
* Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, a...Frédéric Buclin2010-11-036-79/+73
* Bug 608645: Release Notes for Bugzilla 3.4.9Max Kanat-Alexander2010-10-311-0/+6