Search CVE reports


Toggle filters

41 – 50 of 63 results


CVE-2013-3369

Medium priority
Ignored

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary private components via unspecified vectors.

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2013-3368

Medium priority
Ignored

bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-6581

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to bypass intended restrictions on reading keys in the product's keyring, and trigger outbound e-mail messages...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-6580

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, does not ensure that the UI labels unencrypted messages as unencrypted, which might make it easier for remote attackers to spoof...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-6579

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or signing for certain outbound e-mail, and possibly cause a denial of service (loss of...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-6578

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled with a "Sign by default" queue configuration, uses a queue's key for signing, which might allow remote attackers to spoof messages by...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-4884

Medium priority

Some fixes available 3 of 6

Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors related to the GnuPG client.

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-4735

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6578, CVE-2012-6579, CVE-2012-6580, CVE-2012-6581. Reason: This candidate is a duplicate of CVE-2012-6578, CVE-2012-6579, CVE-2012-6580, and CVE-2012-6581. ...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-4734

Medium priority

Some fixes available 3 of 6

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-4733

Medium priority
Ignored

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages