NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 82224 | CVE-2017-5164 | An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary script code in another user's browser session (CROSS-SITE SCRIPTING). | 2 | 4.3 | Medium | 2017-02-28 | 2017-02-16 | View | |
| 82225 | CVE-2017-5165 | An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration. | 2 | 6.8 | Medium | 2017-02-28 | 2017-02-16 | View | |
| 82226 | CVE-2017-5166 | An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. An INFORMATION EXPOSURE flaw can be used to gain privileged access to the device. | 2 | 5 | Medium | 2017-02-28 | 2017-02-16 | View | |
| 82594 | CVE-2017-6000 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | 1 | 2017-02-28 | 2017-02-16 | View | |||
| 82207 | CVE-2017-5141 | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION). | 2 | 6.5 | Medium | 2017-02-28 | 2017-02-17 | View |
Page 15522 of 17672, showing 5 records out of 88360 total, starting on record 77606, ending on 77610