Show filters
113 Total Results
Displaying 101-110 of 113
Sort by:
Attacker Value
Unknown

CVE-2016-2280

Disclosure Date: April 21, 2016 (last updated November 25, 2024)
Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7908

Disclosure Date: December 21, 2015 (last updated October 05, 2023)
Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network.
0
Attacker Value
Unknown

CVE-2015-7907

Disclosure Date: December 21, 2015 (last updated November 25, 2024)
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-2847

Disclosure Date: July 26, 2015 (last updated October 05, 2023)
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.
0
Attacker Value
Unknown

CVE-2015-2848

Disclosure Date: July 26, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Honeywell Tuxedo Touch before 5.2.19.0_VA allows remote attackers to hijack the authentication of arbitrary users for requests associated with home-automation commands, as demonstrated by a door-unlock command.
0
Attacker Value
Unknown

CVE-2015-0984

Disclosure Date: March 31, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.
0
Attacker Value
Unknown

CVE-2014-8269

Disclosure Date: December 13, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in (1) HWOPOSScale.ocx and (2) HWOPOSSCANNER.ocx in Honeywell OPOS Suite before 1.13.4.15 allow remote attackers to execute arbitrary code via a crafted file that is improperly handled by the Open method.
0
Attacker Value
Unknown

CVE-2014-3110

Disclosure Date: July 24, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.
0
Attacker Value
Unknown

CVE-2014-2717

Disclosure Date: July 24, 2014 (last updated October 05, 2023)
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
0
Attacker Value
Unknown

CVE-2013-0108

Disclosure Date: February 24, 2013 (last updated October 05, 2023)
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document.
0