Show filters
192 Total Results
Displaying 21-30 of 192
Sort by:
Attacker Value
Unknown

CVE-2023-5550

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Attacker Value
Unknown

CVE-2023-5549

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
Attacker Value
Unknown

CVE-2023-5548

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
Attacker Value
Unknown

CVE-2023-5545

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Attacker Value
Unknown

CVE-2023-5542

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
Attacker Value
Unknown

CVE-2023-5540

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
Attacker Value
Unknown

CVE-2023-5539

Disclosure Date: November 09, 2023 (last updated April 19, 2024)
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
Attacker Value
Unknown

CVE-2023-3428

Disclosure Date: October 04, 2023 (last updated April 25, 2024)
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
Attacker Value
Unknown

CVE-2022-4318

Disclosure Date: September 25, 2023 (last updated May 03, 2024)
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Attacker Value
Unknown

CVE-2023-39341

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0), and EDR Plus Pack Cloud (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0).