NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 82581 | CVE-2017-5357 | regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free. | 2 | 5 | Medium | 2017-02-28 | 2017-02-17 | View | |
| 81665 | CVE-2017-5595 | A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request. | 2 | 2.1 | Low | 2017-02-28 | 2017-02-16 | View | |
| 82205 | CVE-2017-5139 | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specific URL, because of Plaintext Storage of a Password. | 2 | 5 | Medium | 2017-02-28 | 2017-02-16 | View | |
| 82206 | CVE-2017-5140 | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text. | 2 | 5 | Medium | 2017-02-28 | 2017-02-16 | View | |
| 82208 | CVE-2017-5142 | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the parameters by accessing a specific URL because of Improper Privilege Management. | 2 | 6.5 | Medium | 2017-02-28 | 2017-02-16 | View |
Page 2151 of 17672, showing 5 records out of 88360 total, starting on record 10751, ending on 10755