Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crystal Reports Xi HIGH 9.3
CVE-2008-0379EPSS 9%

Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to …

No fix yet
Fix from $1,950 2008-01-22
Crystal Enterprise HIGH 7.5
CVE-2006-4099

Business Objects Crystal Enterprise 9 and 10 generates predictable session identifiers, which allows remote attackers to hijack sessions of other use…

Patch available
Fix from $1,950 2006-11-29
Crystal Reports Xi HIGH 7.6
CVE-2006-6133EPSS 51%

Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and…

Mitigation only
Fix from $1,950 2006-11-28
Crystal Enterprise Xi MEDIUM 5.0
CVE-2005-4813

Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal R…

Patch available
Fix from $1,600 2005-12-31
Webintelligence MEDIUM 5.0
CVE-2005-4274

Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via u…

No fix yet
Fix from $1,600 2005-12-15
Crystal Enterprise MEDIUM 5.0
CVE-2004-1981

The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without…

Mitigation only
Fix from $1,600 2004-05-02
Webintelligence HIGH 7.5
CVE-2003-1249

WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.

Patch available
Fix from $1,950 2003-12-31
Crystal Reports HIGH 7.5
CVE-2001-1464

Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML p…

No fix yet
Fix from $1,950 2001-01-10