CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
101963 | CVE-2017-5143 | Candidate | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101964 | CVE-2017-5144 | Candidate | An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101965 | CVE-2017-5145 | Candidate | An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101966 | CVE-2017-5146 | Candidate | An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive information is stored in clear-text. | Assigned (20170103) | None (candidate not yet proposed) | View | |
101967 | CVE-2017-5147 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170103) | None (candidate not yet proposed) | View |
Page 19751 of 20943, showing 5 records out of 104715 total, starting on record 98751, ending on 98755