CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87583  CVE-2016-10084  Candidate  admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page["tab"] variable (aka the mode parameter).  Assigned (20161230)  None (candidate not yet proposed)    View
87584  CVE-2016-10085  Candidate  admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.  Assigned (20161230)  None (candidate not yet proposed)    View
87585  CVE-2016-10086  Candidate  RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.  Assigned (20161230)  None (candidate not yet proposed)    View
87586  CVE-2016-10087  Candidate  The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.  Assigned (20161230)  None (candidate not yet proposed)    View
87587  CVE-2016-10088  Candidate  The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-free) by leveraging access to a /dev/sg device, related to block/bsg.c and drivers/scsi/sg.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9576.  Assigned (20161230)  None (candidate not yet proposed)    View

Page 1227 of 20943, showing 5 records out of 104715 total, starting on record 6131, ending on 6135

Actions