CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26961  CVE-2007-3604  Candidate  vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.  Assigned (20070706)  None (candidate not yet proposed)    View
26956  CVE-2007-3599  Candidate  vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permission.  Assigned (20070706)  None (candidate not yet proposed)    View
20692  CVE-2006-4588  Candidate  vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to index.php with a modified module parameter, as demonstrated using the Settings module.  Assigned (20060906)  None (candidate not yet proposed)    View
6899  CVE-2003-0070  Entry  VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user"s terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.        View
22553  CVE-2006-6449  Candidate  Vt-Forum Lite 1.3 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20061210)  None (candidate not yet proposed)    View

Page 500 of 20943, showing 5 records out of 104715 total, starting on record 2496, ending on 2500

Actions