CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
52591 | CVE-2011-4679 | Candidate | vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report. | Assigned (20111206) | None (candidate not yet proposed) | View | |
40693 | CVE-2009-3258 | Candidate | vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) views, and (5) tickets; insert (6) attachments, (7) reports, (8) filters, (9) views, and (10) tickets; and edit (11) reports, (12) filters, (13) views, and (14) tickets via unspecified vectors. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40692 | CVE-2009-3257 | Candidate | vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile. | Assigned (20090918) | None (candidate not yet proposed) | View | |
33575 | CVE-2008-3458 | Candidate | Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory. | Assigned (20080804) | None (candidate not yet proposed) | View | |
26958 | CVE-2007-3601 | Candidate | vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users" calendar activities via a (1) home page or (2) event list view. | Assigned (20070706) | None (candidate not yet proposed) | View |
Page 499 of 20943, showing 5 records out of 104715 total, starting on record 2491, ending on 2495