Show filters
43 Total Results
Displaying 21-30 of 43
Sort by:
Attacker Value
Unknown
CVE-2022-45152
Disclosure Date: November 25, 2022 (last updated October 08, 2023)
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
0
Attacker Value
Unknown
CVE-2022-0367
Disclosure Date: August 29, 2022 (last updated October 08, 2023)
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
0
Attacker Value
Unknown
CVE-2020-14394
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2022-32546
Disclosure Date: June 16, 2022 (last updated October 07, 2023)
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
0
Attacker Value
Unknown
CVE-2022-32545
Disclosure Date: June 16, 2022 (last updated October 07, 2023)
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
0
Attacker Value
Unknown
CVE-2022-28327
Disclosure Date: April 20, 2022 (last updated October 07, 2023)
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
0
Attacker Value
Unknown
CVE-2022-0983
Disclosure Date: March 25, 2022 (last updated October 07, 2023)
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
0
Attacker Value
Unknown
CVE-2022-0725
Disclosure Date: March 10, 2022 (last updated November 29, 2024)
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
0
Attacker Value
Unknown
CVE-2021-3733
Disclosure Date: March 10, 2022 (last updated November 29, 2024)
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
0
Attacker Value
Unknown
CVE-2022-0546
Disclosure Date: February 24, 2022 (last updated October 07, 2023)
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
0