CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52591  CVE-2011-4679  Candidate  vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.  Assigned (20111206)  None (candidate not yet proposed)    View
40693  CVE-2009-3258  Candidate  vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) views, and (5) tickets; insert (6) attachments, (7) reports, (8) filters, (9) views, and (10) tickets; and edit (11) reports, (12) filters, (13) views, and (14) tickets via unspecified vectors.  Assigned (20090918)  None (candidate not yet proposed)    View
40692  CVE-2009-3257  Candidate  vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.  Assigned (20090918)  None (candidate not yet proposed)    View
33575  CVE-2008-3458  Candidate  Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.  Assigned (20080804)  None (candidate not yet proposed)    View
26958  CVE-2007-3601  Candidate  vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users" calendar activities via a (1) home page or (2) event list view.  Assigned (20070706)  None (candidate not yet proposed)    View

Page 499 of 20943, showing 5 records out of 104715 total, starting on record 2491, ending on 2495

Actions