CVE-2023-5542
- EPSS 0.27%
- Veröffentlicht 09.11.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:41:58
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
CVE-2023-5544
- EPSS 0.13%
- Veröffentlicht 09.11.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:41:58
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
CVE-2023-5545
- EPSS 0.28%
- Veröffentlicht 09.11.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:41:58
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
CVE-2023-39198
- EPSS 0.01%
- Veröffentlicht 09.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:14:53
A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allow...
CVE-2023-5539
- EPSS 1.83%
- Veröffentlicht 09.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:41:58
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
CVE-2023-5996
- EPSS 0.74%
- Veröffentlicht 08.11.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:56
Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-4535
- EPSS 0.22%
- Veröffentlicht 06.11.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:35:21
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or s...
CVE-2023-47272
- EPSS 0.65%
- Veröffentlicht 06.11.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:05
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
CVE-2023-3961
- EPSS 1.94%
- Veröffentlicht 03.11.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:24
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services ...
CVE-2023-4091
- EPSS 0.48%
- Veröffentlicht 03.11.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 08:34:22
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows openi...