FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  351364
Date:      2014-04-15
Time:      20:21:44Z
Committer: swills

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
49a6026a-52a3-11e2-a289-1c4bd681f0cfotrs -- XSS vulnerability in Internet Explorer

OTRS Security Advisory reports:

This advisory covers vulnerabilities discovered in the OTRS core system. Due to the XSS vulnerability in Internet Explorer an attacker could send a specially prepared HTML email to OTRS which would cause JavaScript code to be executed in your Internet Explorer while displaying the email.


Discovery 2012-08-22
Entry 2012-12-30
otrs
lt 3.1.9

CVE-2012-2582
http://www.otrs.com/open-source/community-news/security-advisories/security-advisory-2012-01/
13320091-52a6-11e2-a289-1c4bd681f0cfotrs -- XSS vulnerability

OTRS Security Advisory reports:

This advisory covers vulnerabilities discovered in the OTRS core system. This is a variance of the XSS vulnerability, where an attacker could send a specially prepared HTML email to OTRS which would cause JavaScript code to be executed in your browser while displaying the email. In this case this is achieved by using javascript source attributes with whitespaces.


Discovery 2012-10-16
Entry 2012-12-30
otrs
lt 3.1.11

CVE-2012-4751
http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-03/
http://www.kb.cert.org/vuls/id/603276
86baa0d4-c997-11e0-8a8e-00151735203aOTRS -- Vulnerabilities in OTRS-Core allows read access to any file on local file system

OTRS Security Advisory reports:

  • An attacker with valid session and admin permissions could get read access to any file on the servers local operating system. For this it would be needed minimum one installed OTRS package.

Discovery 2011-08-16
Entry 2011-08-18
otrs
gt 2.1.* lt 3.0.10

CVE-2011-2746
http://otrs.org/advisory/OSA-2011-03-en/
95a69d1a-52a5-11e2-a289-1c4bd681f0cfotrs -- XSS vulnerability in Firefox and Opera

OTRS Security Advisory reports:

This advisory covers vulnerabilities discovered in the OTRS core system. This is a variance of the XSS vulnerability, where an attacker could send a specially prepared HTML email to OTRS which would cause JavaScript code to be executed in your browser while displaying the email in Firefox and Opera. In this case this is achieved with an invalid HTML structure with nested tags.


Discovery 2012-08-30
Entry 2012-12-30
otrs
lt 3.1.10

CVE-2012-4600
http://www.otrs.com/open-source/community-news/security-advisories/security-advisory-2012-02/
86baa0d4-c997-11e0-8a8e-00151735203aOTRS -- Vulnerabilities in OTRS-Core allows read access to any file on local file system

OTRS Security Advisory reports:

  • An attacker with valid session and admin permissions could get read access to any file on the servers local operating system. For this it would be needed minimum one installed OTRS package.

Discovery 2011-08-16
Entry 2011-08-18
otrs
gt 2.1.* lt 3.0.10

CVE-2011-2746
http://otrs.org/advisory/OSA-2011-03-en/