Search CVE reports
171 – 180 of 40333 results
BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP...
1 affected package
bluez-alsa
| Package | 26.04 LTS |
|---|---|
| bluez-alsa | Needs evaluation |
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client...
1 affected package
iperf3
| Package | 26.04 LTS |
|---|---|
| iperf3 | Needs evaluation |
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a...
1 affected package
iperf3
| Package | 26.04 LTS |
|---|---|
| iperf3 | Needs evaluation |
Not in release
A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |
Not in release
A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its...
1 affected package
moodle
| Package | 26.04 LTS |
|---|---|
| moodle | Not in release |