CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
101958 | CVE-2017-5138 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101959 | CVE-2017-5139 | Candidate | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specific URL, because of Plaintext Storage of a Password. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101960 | CVE-2017-5140 | Candidate | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101961 | CVE-2017-5141 | Candidate | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION). | Assigned (20170103) | None (candidate not yet proposed) | View | |
101962 | CVE-2017-5142 | Candidate | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the parameters by accessing a specific URL because of Improper Privilege Management. | Assigned (20170103) | None (candidate not yet proposed) | View |
Page 19750 of 20943, showing 5 records out of 104715 total, starting on record 98746, ending on 98750