Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

51 – 58 of 58 results


CVE-2011-5092

Medium priority
Ignored

Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vulnerability than CVE-2011-4458 and CVE-2011-5093.

3 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
Show less packages

CVE-2011-4460

Low priority
Ignored

SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to execute arbitrary SQL commands by leveraging access to a privileged account.

4 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4, rt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
rt Not in release
Show less packages

CVE-2011-4459

Low priority
Ignored

Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging...

4 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4, rt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
rt Not in release
Show less packages

CVE-2011-4458

Medium priority

Some fixes available 3 of 7

Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different...

4 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4, rt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
rt Not in release
Show less packages

CVE-2011-2085

Medium priority

Some fixes available 3 of 7

Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users.

4 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4, rt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
rt Not in release
Show less packages

CVE-2011-2084

Low priority

Some fixes available 3 of 7

Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ticket correspondence history by leveraging access to a privileged account.

4 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4, rt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
rt Not in release
Show less packages

CVE-2011-2083

Medium priority

Some fixes available 3 of 7

Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4, rt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
rt Not in release
Show less packages

CVE-2011-2082

Low priority

Some fixes available 3 of 7

The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which makes it easier for context-dependent attackers to...

3 affected packages

request-tracker3.6, request-tracker3.8, request-tracker4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
request-tracker3.6 Not in release
request-tracker3.8 Not in release
request-tracker4 Not affected
Show less packages