CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
87582 | CVE-2016-10083 | Candidate | Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case. | Assigned (20161230) | None (candidate not yet proposed) | View | |
87583 | CVE-2016-10084 | Candidate | admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page["tab"] variable (aka the mode parameter). | Assigned (20161230) | None (candidate not yet proposed) | View | |
87584 | CVE-2016-10085 | Candidate | admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter. | Assigned (20161230) | None (candidate not yet proposed) | View | |
87585 | CVE-2016-10086 | Candidate | RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request. | Assigned (20161230) | None (candidate not yet proposed) | View | |
87586 | CVE-2016-10087 | Candidate | The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure. | Assigned (20161230) | None (candidate not yet proposed) | View |
Page 19717 of 20943, showing 5 records out of 104715 total, starting on record 98581, ending on 98585