Search CVE reports
151 – 160 of 33481 results
Not in release
A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.
1 affected package
moodle
| Package | 22.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
1 affected package
moodle
| Package | 22.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.
1 affected package
moodle
| Package | 22.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
1 affected package
moodle
| Package | 22.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.
1 affected package
moodle
| Package | 22.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to,...
1 affected package
moodle
| Package | 22.04 LTS |
|---|---|
| moodle | Not in release |
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing...
2 affected packages
libsoup2.4, libsoup3
| Package | 22.04 LTS |
|---|---|
| libsoup2.4 | Needs evaluation |
| libsoup3 | Needs evaluation |
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in...
1 affected package
lz4
| Package | 22.04 LTS |
|---|---|
| lz4 | Not affected |
Not in release
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using...
1 affected package
pypdf
| Package | 22.04 LTS |
|---|---|
| pypdf | Not in release |
Not in release
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has...
1 affected package
pypdf
| Package | 22.04 LTS |
|---|---|
| pypdf | Not in release |