Show filters
168 Total Results
Displaying 111-120 of 168
Sort by:
Attacker Value
Unknown

CVE-2012-1170

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
Attacker Value
Unknown

CVE-2012-1161

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
Attacker Value
Unknown

CVE-2012-1168

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
Attacker Value
Unknown

CVE-2012-1155

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
Attacker Value
Unknown

CVE-2012-1156

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle before 2.2.2 has users' private files included in course backups
Attacker Value
Unknown

CVE-2019-14379

Disclosure Date: November 12, 2019 (last updated November 08, 2023)
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
Attacker Value
Unknown

CVE-2013-1820

Disclosure Date: November 08, 2019 (last updated November 27, 2024)
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
Attacker Value
Unknown

CVE-2013-1930

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
Attacker Value
Unknown

CVE-2013-1931

Disclosure Date: October 31, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
Attacker Value
Unknown

CVE-2019-16335

Disclosure Date: September 15, 2019 (last updated November 08, 2023)
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.