Vulnerabilities > Bestpractical > Request Tracker > 4.2.6

DATE CVE VULNERABILITY TITLE RISK
2015-03-09 CVE-2015-1464 Improper Access Control vulnerability in multiple products
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
network
low complexity
fedoraproject bestpractical CWE-284
6.4
2015-03-09 CVE-2015-1165 Information Exposure vulnerability in multiple products
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
network
low complexity
debian fedoraproject bestpractical CWE-200
5.0
2015-03-09 CVE-2014-9472 Resource Management Errors vulnerability in multiple products
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
7.1