CVE-2022-1949
- EPSS 0.51%
- Published 02.06.2022 14:15:34
- Last modified 13.12.2024 18:47:19
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unau...
CVE-2022-1789
- EPSS 0.02%
- Published 02.06.2022 14:15:33
- Last modified 21.11.2024 06:41:28
With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
CVE-2022-1462
- EPSS 0.04%
- Published 02.06.2022 14:15:32
- Last modified 21.11.2024 06:40:46
An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc functi...
CVE-2022-1652
- EPSS 0.2%
- Published 02.06.2022 14:15:32
- Last modified 21.11.2024 06:41:10
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to exe...
CVE-2022-30597
- EPSS 0.53%
- Published 18.05.2022 18:15:10
- Last modified 21.11.2024 07:02:59
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
CVE-2022-30598
- EPSS 0.51%
- Published 18.05.2022 18:15:10
- Last modified 21.11.2024 07:03:00
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
CVE-2022-30599
- EPSS 0.82%
- Published 18.05.2022 18:15:10
- Last modified 21.11.2024 07:03:00
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
CVE-2022-30600
- EPSS 3.93%
- Published 18.05.2022 18:15:10
- Last modified 21.11.2024 07:03:00
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
CVE-2022-30596
- EPSS 1.16%
- Published 18.05.2022 17:15:08
- Last modified 21.11.2024 07:02:59
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
CVE-2022-1706
- EPSS 0.27%
- Published 17.05.2022 18:15:08
- Last modified 21.11.2024 06:41:17
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threa...