Show filters
151 Total Results
Displaying 141-150 of 151
Sort by:
Attacker Value
Unknown
CVE-2017-5166
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. An INFORMATION EXPOSURE flaw can be used to gain privileged access to the device.
0
Attacker Value
Unknown
CVE-2017-5167
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.
0
Attacker Value
Unknown
CVE-2017-5165
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.
0
Attacker Value
Unknown
CVE-2017-5164
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary script code in another user's browser session (CROSS-SITE SCRIPTING).
0
Attacker Value
Unknown
CVE-2017-5162
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configuration.
0
Attacker Value
Unknown
CVE-2014-7180
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.
0
Attacker Value
Unknown
CVE-2014-6683
Disclosure Date: September 23, 2014 (last updated October 05, 2023)
The Open Electrical Webser (aka com.wOpenElectricalWeb) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2013-3665
Disclosure Date: July 18, 2013 (last updated October 05, 2023)
Unspecified vulnerability in Autodesk AutoCAD through 2014, AutoCAD LT through 2014, and DWG TrueView through 2014 allows remote attackers to execute arbitrary code via a crafted DWG file.
0
Attacker Value
Unknown
CVE-2005-4710
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329.
0
Attacker Value
Unknown
CVE-2005-4582
Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Electric Sheep 2.6.3 does not require authentication or integrity checks from the server to the client, which allows remote attackers to download and display arbitrary MPEG movie files via (1) DNS spoofing, (2) a URL on the command line, or (3) a URL in the configuration file. NOTE: the same attack vectors apply to common web browsers that are able to communicate with untrusted web servers, and other problems related to DNS design issues. Therefore this may not be a specific vulnerability. However, a client would reasonably expect to receive content only from the server.
0