CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users ga...Show more |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versio...Show more |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3....Show more |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected...Show more |
4C Ares Project FedoraprojectNodejs+1 more8Blockchain Platform C AresFedora+5 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a D...Show more |
3Fedoraproject GolangNetapp4Cloud Insights Telegraf Agent FedoraGo+1 moreJun 17, 2026 Nov 18, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file. |
3Fedoraproject GolangNetapp4Cloud Insights Telegraf Agent FedoraGo+1 moreJun 17, 2026 Nov 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. |
5Debian FedoraprojectIntel+2 more17Clustered Data Ontap Debian LinuxFedora+14 moreJun 17, 2026 Nov 12, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
4Debian FedoraprojectIntel+1 more7Clustered Data Ontap Debian LinuxFedora+4 moreJun 17, 2026 Nov 12, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
3Debian FedoraprojectIntel301Celeron 3855u Firmware Celeron 3865u FirmwareCeleron 3955u Firmware+298 moreJun 17, 2026 Nov 12, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. |
3Fedoraproject Python Rsa ProjectRedhat3Fedora Openstack PlatformPython RsaJun 17, 2026 Nov 12, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 10, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE:...Show more |
2Fedoraproject Google2Android FedoraJun 17, 2026 Nov 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data wi...Show more |
3Debian FedoraprojectLibrdf3Debian Linux FedoraRaptor Rdf Syntax LibraryNov 21, 2024 Nov 6, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen i...Show more |
4Fedoraproject MitNetapp+1 more11Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Nov 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recurs...Show more |
2Fedoraproject Linuxfoundation2Fedora Nats ServerJun 17, 2026 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled. |
2Fedoraproject Linuxfoundation2Fedora Nats ServerJun 17, 2026 Nov 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code). |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. |
4Asterisk DebianFedoraproject+1 more4Asterisk Certified AsteriskDebian Linux+1 moreJun 17, 2026 Nov 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVI...Show more |
3Debian FedoraprojectMaxmind3Debian Linux FedoraLibmaxminddbJun 17, 2026 Nov 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c. |