CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104008  CVE-2017-7188  Candidate  Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.  Assigned (20170320)  None (candidate not yet proposed)    View
71450  CVE-2014-4154  Candidate  ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js.  Assigned (20140612)  None (candidate not yet proposed)    View
84528  CVE-2015-7251  Candidate  ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.  Assigned (20150918)  None (candidate not yet proposed)    View
85980  CVE-2015-8703  Candidate  ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248.  Assigned (20151229)  None (candidate not yet proposed)    View
84526  CVE-2015-7249  Candidate  ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.  Assigned (20150918)  None (candidate not yet proposed)    View

Page 8 of 20943, showing 5 records out of 104715 total, starting on record 36, ending on 40

<<first 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 last>>

Actions