NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50463 | CVE-2009-3258 | vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) views, and (5) tickets; insert (6) attachments, (7) reports, (8) filters, (9) views, and (10) tickets; and edit (11) reports, (12) filters, (13) views, and (14) tickets via unspecified vectors. | 2 | 9 | High | 2017-01-07 | 2009-09-21 | View | |
50462 | CVE-2009-3257 | vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile. | 2 | 3.6 | Low | 2017-01-07 | 2009-09-22 | View | |
3339 | CVE-2008-3458 | Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
55751 | CVE-2007-3601 | vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users" calendar activities via a (1) home page or (2) event list view. | 2 | 2.1 | Low | 2017-01-07 | 2008-11-15 | View | |
55754 | CVE-2007-3604 | vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php. | 2 | 4 | Medium | 2017-01-07 | 2008-11-13 | View |
Page 573 of 17672, showing 5 records out of 88360 total, starting on record 2861, ending on 2865