Search CVE reports


Toggle filters

41 – 50 of 63 results


CVE-2013-3368

Medium priority
Ignored

bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-4733

Medium priority
Ignored

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-6581

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to bypass intended restrictions on reading keys in the product's keyring, and trigger outbound e-mail messages...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-6580

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, does not ensure that the UI labels unencrypted messages as unencrypted, which might make it easier for remote attackers to spoof...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-6579

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or signing for certain outbound e-mail, and possibly cause a denial of service (loss of...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-6578

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled with a "Sign by default" queue configuration, uses a queue's key for signing, which might allow remote attackers to spoof messages by...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2012-4735

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6578, CVE-2012-6579, CVE-2012-6580, CVE-2012-6581. Reason: This candidate is a duplicate of CVE-2012-6578, CVE-2012-6579, CVE-2012-6580, and CVE-2012-6581. ...

2 affected packages

request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker3.8
request-tracker4
Show less packages

CVE-2013-3525

Medium priority
Ignored

SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-4884

Medium priority

Some fixes available 3 of 6

Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors related to the GnuPG client.

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages

CVE-2012-4734

Medium priority

Some fixes available 3 of 6

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via...

2 affected packages

request-tracker4, request-tracker3.8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
request-tracker4
request-tracker3.8
Show less packages