Show filters
174 Total Results
Displaying 121-130 of 174
Sort by:
Attacker Value
Unknown

CVE-2014-9472

Disclosure Date: March 09, 2015 (last updated October 05, 2023)
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
0
Attacker Value
Unknown

CVE-2015-1464

Disclosure Date: March 09, 2015 (last updated October 05, 2023)
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
0
Attacker Value
Unknown

CVE-2015-1165

Disclosure Date: March 09, 2015 (last updated October 05, 2023)
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-0109

Disclosure Date: February 18, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0108.
0
Attacker Value
Unknown

CVE-2015-0108

Disclosure Date: February 18, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0109.
0
Attacker Value
Unknown

CVE-2014-6102

Disclosure Date: February 17, 2015 (last updated October 05, 2023)
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly handle logout actions, which allows remote attackers to bypass intended Cognos BI Direct Integration access restrictions by leveraging an unattended workstation.
0
Attacker Value
Unknown

CVE-2014-6194

Disclosure Date: February 17, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to read arbitrary files via a .. (dot dot) in a pathname.
0
Attacker Value
Unknown

CVE-2013-3737

Disclosure Date: November 16, 2014 (last updated October 05, 2023)
The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-1829

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
0
Attacker Value
Unknown

CVE-2014-1830

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
0