CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The course upload preview contained an XSS risk for users uploading unsafe data. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 H5P metadata automatically populated the author with the user's username, which could be sensitive information. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Students in "Only see own membership" groups could see other students in the group, which should be hidden. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Nov 9, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a re...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 8, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Nov 6, 2023 N/A· v4 3.8 LOW· v3 N/A· v2 An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a spe...Show more |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Nov 6, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote...Show more |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes"....Show more |
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unr...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Nov 3, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed pa...Show more |
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via c...Show more |
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files. |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode cha...Show more |