NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88011 | CVE-2017-6028 | An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application. | 2 | 5 | Medium | 2017-07-18 | 2017-07-07 | View | |
88267 | CVE-2017-9905 | XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to Data from Faulting Address controls Branch Selection starting at Xfpx!gffGetFormatInfo+0x00000000000228e8. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
65996 | CVE-2005-0232 | Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing." | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
66252 | CVE-2005-0495 | Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
66508 | CVE-2005-0758 | zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 1102 of 17672, showing 5 records out of 88360 total, starting on record 5506, ending on 5510