CVE-2024-25981
- EPSS 0.16%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:45:12
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25982
- EPSS 0.21%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:42:27
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVE-2024-25983
- EPSS 0.14%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 17:37:14
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25978
- EPSS 0.21%
- Veröffentlicht 19.02.2024 17:15:08
- Zuletzt bearbeitet 23.01.2025 16:47:38
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-25979
- EPSS 0.13%
- Veröffentlicht 19.02.2024 17:15:08
- Zuletzt bearbeitet 23.01.2025 16:47:30
The URL parameters accepted by forum search were not limited to the allowed parameters.
CVE-2024-1597
- EPSS 0.31%
- Veröffentlicht 19.02.2024 13:15:07
- Zuletzt bearbeitet 12.06.2025 16:15:21
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus....
CVE-2024-1580
- EPSS 0.36%
- Veröffentlicht 19.02.2024 11:15:08
- Zuletzt bearbeitet 13.02.2025 18:16:25
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
CVE-2023-50387
- EPSS 42.22%
- Veröffentlicht 14.02.2024 16:15:45
- Zuletzt bearbeitet 12.05.2025 15:15:56
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that,...
CVE-2024-24814
- EPSS 0.21%
- Veröffentlicht 13.02.2024 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:59:46
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_...
CVE-2023-4408
- EPSS 0.3%
- Veröffentlicht 13.02.2024 14:15:45
- Zuletzt bearbeitet 14.03.2025 17:15:40
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` insta...