NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87638  CVE-2017-10681  Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.    6.8  Medium  2017-07-18  2017-07-04  View
87637  CVE-2017-10680  Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.    6.8  Medium  2017-07-18  2017-07-03  View
87636  CVE-2017-10679  Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.    Medium  2017-07-18  2017-07-05  View
87635  CVE-2017-10678  Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.    6.8  Medium  2017-07-18  2017-07-05  View
87634  CVE-2017-10674  Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.    4.9  Medium  2017-07-18  2017-07-06  View

Page 834 of 17672, showing 5 records out of 88360 total, starting on record 4166, ending on 4170

Actions