CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37651  CVE-2009-0216  Candidate  GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.  Assigned (20090120)  None (candidate not yet proposed)    View
103187  CVE-2017-6367  Candidate  In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.  Assigned (20170228)  None (candidate not yet proposed)    View
37907  CVE-2009-0472  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20090206)  None (candidate not yet proposed)    View
103443  CVE-2017-6623  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170309)  None (candidate not yet proposed)    View
38163  CVE-2009-0728  Candidate  SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.  Assigned (20090224)  None (candidate not yet proposed)    View

Page 1568 of 20943, showing 5 records out of 104715 total, starting on record 7836, ending on 7840

Actions