VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-30598MedMay 18, 2022
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

  • CVE-2022-0984MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

  • CVE-2021-3981LowMar 10, 2022
    risk 0.21cvss 3.3epss 0.00

    A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted…

  • CVE-2021-37964LowOct 8, 2021
    risk 0.21cvss 3.3epss 0.01

    Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.

  • CVE-2021-20239LowMay 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.

  • CVE-2021-25317LowMay 5, 2021
    risk 0.21cvss 3.3epss 0.00

    A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root…

  • CVE-2020-29623LowApr 2, 2021
    risk 0.21cvss 3.3epss 0.00

    "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be…

  • CVE-2021-3392LowMar 23, 2021
    risk 0.21cvss 3.2epss 0.00

    A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest…

  • CVE-2021-20283MedMar 15, 2021
    risk 0.21cvss 4.3epss 0.01

    The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-21274MedFeb 26, 2021
    risk 0.21cvss 4.3epss 0.02

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large…

  • CVE-2020-11867LowNov 30, 2020
    risk 0.21cvss 3.3epss 0.00

    Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.

  • CVE-2019-13033LowJun 18, 2020
    risk 0.21cvss 3.3epss 0.00

    In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing the license key, it may be…

  • CVE-2020-8551MedMar 27, 2020
    risk 0.21cvss 4.3epss 0.01

    The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API…

  • CVE-2019-13762LowDec 10, 2019
    risk 0.21cvss 3.3epss 0.00

    Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.

  • CVE-2012-1159MedNov 14, 2019
    risk 0.21cvss 4.3epss 0.01

    Moodle before 2.2.2: Overview report allows users to see hidden courses

  • CVE-2012-1157MedNov 14, 2019
    risk 0.21cvss 4.3epss 0.01

    Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default

  • CVE-2019-3851MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

  • CVE-2017-9271LowMar 1, 2018
    risk 0.21cvss 3.3epss 0.00

    The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.

  • CVE-2015-5069MedSep 26, 2017
    risk 0.21cvss 4.3epss 0.02

    The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl…

  • CVE-2016-9085LowFeb 3, 2017
    risk 0.21cvss 3.3epss 0.00

    Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.

Page 206 of 268