CVE List

Id CVE No. Status Description Phase Votes Comments Actions
101958  CVE-2017-5138  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170103)  None (candidate not yet proposed)    View
101959  CVE-2017-5139  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specific URL, because of Plaintext Storage of a Password.  Assigned (20170103)  None (candidate not yet proposed)    View
101960  CVE-2017-5140  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.  Assigned (20170103)  None (candidate not yet proposed)    View
101961  CVE-2017-5141  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION).  Assigned (20170103)  None (candidate not yet proposed)    View
101962  CVE-2017-5142  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the parameters by accessing a specific URL because of Improper Privilege Management.  Assigned (20170103)  None (candidate not yet proposed)    View

Page 19750 of 20943, showing 5 records out of 104715 total, starting on record 98746, ending on 98750

Actions