CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87827  CVE-2016-10306  Candidate  Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87828  CVE-2016-10307  Candidate  Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87829  CVE-2016-10308  Candidate  Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device"s web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.  Assigned (20170329)  None (candidate not yet proposed)    View
87830  CVE-2016-10309  Candidate  In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.  Assigned (20170329)  None (candidate not yet proposed)    View
104118  CVE-2017-7298  Candidate  In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.  Assigned (20170329)  None (candidate not yet proposed)    View

Page 702 of 20943, showing 5 records out of 104715 total, starting on record 3506, ending on 3510

Actions