Show filters
1,213 Total Results
Displaying 261-270 of 1,213
Sort by:
Attacker Value
Unknown

CVE-2022-1789

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
Attacker Value
Unknown

CVE-2022-30600

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Attacker Value
Unknown

CVE-2022-30599

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Attacker Value
Unknown

CVE-2022-30598

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
Attacker Value
Unknown

CVE-2022-30597

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Attacker Value
Unknown

CVE-2022-30596

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
Attacker Value
Unknown

CVE-2022-1706

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Attacker Value
Unknown

CVE-2022-1586

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
Attacker Value
Unknown

CVE-2022-1587

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
Attacker Value
Unknown

CVE-2022-1292

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).