VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-30159MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's only called if…

  • CVE-2021-30156MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists.

  • CVE-2021-30155MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.

  • CVE-2021-30152MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.

  • CVE-2021-20282MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20281MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20280MedMar 15, 2021
    risk 0.28cvss 5.4epss 0.01

    Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20279MedMar 15, 2021
    risk 0.28cvss 5.4epss 0.01

    The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-21189MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-21187MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2021-21186MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.

  • CVE-2021-21185MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.

  • CVE-2021-21184MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21183MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-20229MedFeb 23, 2021
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.

  • CVE-2021-21147MedFeb 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-3281MedFeb 2, 2021
    risk 0.28cvss 5.3epss 0.08

    In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.

  • CVE-2020-28493MedFeb 1, 2021
    risk 0.28cvss 5.3epss 0.04

    This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be…

  • CVE-2020-35655MedJan 12, 2021
    risk 0.28cvss 5.4epss 0.02

    In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

  • CVE-2020-0499MedDec 15, 2020
    risk 0.28cvss 4.3epss 0.04

    In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

Page 195 of 268