NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17439  CVE-2016-10083  Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.    4.3  Medium  2017-01-19  2017-01-03  View
17440  CVE-2016-10084  admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page["tab"] variable (aka the mode parameter).    6.5  Medium  2017-01-19  2017-01-03  View
17441  CVE-2016-10085  admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.    6.5  Medium  2017-01-19  2017-01-03  View
17442  CVE-2016-10086  RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.          2017-01-19  2017-01-18  View
81983  CVE-2016-10087  The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure, removing the text, and then adding another text chunk to the structure.    Medium  2017-02-28  2017-02-28  View

Page 15348 of 17672, showing 5 records out of 88360 total, starting on record 76736, ending on 76740

Actions