CVE List

Id CVE No. Status Description Phase Votes Comments Actions
101963  CVE-2017-5143  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.  Assigned (20170103)  None (candidate not yet proposed)    View
101964  CVE-2017-5144  Candidate  An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication.  Assigned (20170103)  None (candidate not yet proposed)    View
101965  CVE-2017-5145  Candidate  An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.  Assigned (20170103)  None (candidate not yet proposed)    View
101966  CVE-2017-5146  Candidate  An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive information is stored in clear-text.  Assigned (20170103)  None (candidate not yet proposed)    View
101967  CVE-2017-5147  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170103)  None (candidate not yet proposed)    View

Page 19751 of 20943, showing 5 records out of 104715 total, starting on record 98751, ending on 98755

Actions