NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20884 | CVE-2016-5668 | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call. | 2 | 7.5 | High | 2017-01-19 | 2016-08-15 | View | |
20885 | CVE-2016-5669 | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier for remote attackers to conduct man-in-the-middle attacks against HTTPS sessions by leveraging the certificate"s trust relationship. | 2 | 5 | Medium | 2017-01-19 | 2016-08-15 | View | |
20886 | CVE-2016-5670 | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via the web management interface. | 2 | 10 | High | 2017-01-19 | 2016-08-15 | View | |
20887 | CVE-2016-5671 | Multiple cross-site request forgery (CSRF) vulnerabilities on Crestron Electronics DM-TXRX-100-STR devices with firmware through 1.3039.00040 allow remote attackers to hijack the authentication of arbitrary users. | 2 | 6.8 | Medium | 2017-01-19 | 2016-08-16 | View | |
20888 | CVE-2016-5672 | Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user"s acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it easier for man-in-the-middle attackers to spoof SSL servers and obtain sensitive information via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2016-08-16 | View |
Page 16151 of 17672, showing 5 records out of 88360 total, starting on record 80751, ending on 80755