CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Moodle2Fedora MoodleMay 6, 2026 Feb 22, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not cons...Show more |
2Fedoraproject Phpmyadmin2Fedora PhpmyadminMay 6, 2026 Feb 20, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response. |
2Fedoraproject Phpmyadmin2Fedora PhpmyadminMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) ta...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrict...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraVm Server+1 moreMay 6, 2026 Feb 19, 2016 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreMay 6, 2026 Feb 16, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended val...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attack...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote a...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreMay 6, 2026 Feb 8, 2016 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a ze...Show more |
2Fedoraproject Greenbone3Fedora Greenbone OsGreenbone Security AssistantMay 6, 2026 Jan 26, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a ge...Show more |
5Canonical DebianEcryptfs+2 more6Debian Linux Ecryptfs UtilsFedora+3 moreMay 6, 2026 Jan 22, 2016 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid. |
2Cgit Project Fedoraproject2Cgit FedoraMay 6, 2026 Jan 20, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow. |
2Cgit Project Fedoraproject2Cgit FedoraMay 6, 2026 Jan 20, 2016 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP r...Show more |