CVE-2012-1155
- EPSS 1.27%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:33
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2012-1156
- EPSS 1.23%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:33
Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-1168
- EPSS 2.22%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:34
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2011-1145
- EPSS 0.22%
- Veröffentlicht 14.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 01:25:39
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
CVE-2010-4664
- EPSS 0.19%
- Veröffentlicht 13.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:28
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
CVE-2010-4657
- EPSS 1.57%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
CVE-2010-4661
- EPSS 0.15%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
CVE-2011-2897
- EPSS 0.99%
- Veröffentlicht 12.11.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 01:29:13
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
CVE-2019-14824
- EPSS 0.19%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:26
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
CVE-2019-18811
- EPSS 0.13%
- Veröffentlicht 07.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:37
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380...