CVE-2024-21812
- EPSS 0.35%
- Veröffentlicht 20.02.2024 16:15:08
- Zuletzt bearbeitet 04.11.2025 19:16:30
An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary ...
CVE-2024-22097
- EPSS 0.33%
- Veröffentlicht 20.02.2024 16:15:08
- Zuletzt bearbeitet 04.11.2025 19:16:31
A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a mali...
CVE-2024-23305
- EPSS 0.66%
- Veröffentlicht 20.02.2024 16:15:08
- Zuletzt bearbeitet 04.11.2025 19:16:53
An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provid...
CVE-2024-26134
- EPSS 0.83%
- Veröffentlicht 19.02.2024 23:15:07
- Zuletzt bearbeitet 02.01.2025 14:18:48
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, an attacker can crash a service using cbor2 to parse a CBOR binary by send...
CVE-2024-25980
- EPSS 0.13%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:47:04
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25981
- EPSS 0.16%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:45:12
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25982
- EPSS 0.21%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 16:42:27
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVE-2024-25983
- EPSS 0.14%
- Veröffentlicht 19.02.2024 17:15:09
- Zuletzt bearbeitet 23.01.2025 17:37:14
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25978
- EPSS 0.21%
- Veröffentlicht 19.02.2024 17:15:08
- Zuletzt bearbeitet 23.01.2025 16:47:38
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-25979
- EPSS 0.13%
- Veröffentlicht 19.02.2024 17:15:08
- Zuletzt bearbeitet 23.01.2025 16:47:30
The URL parameters accepted by forum search were not limited to the allowed parameters.