Search CVE reports


Toggle filters

7381 – 7390 of 57173 results


CVE-2024-36845

Medium priority
Needs evaluation

An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.

1 affected package

libmodbus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmodbus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-36844

Medium priority
Needs evaluation

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.

1 affected package

libmodbus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmodbus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-36843

Medium priority
Needs evaluation

libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.

1 affected package

libmodbus

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libmodbus Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-34001

Medium priority
Needs evaluation

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-34000

Medium priority
Needs evaluation

ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-33999

Medium priority
Needs evaluation

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-33998

Medium priority
Needs evaluation

Insufficient escaping of participants’ names in the participants page table resulted in a stored XSS risk when interacting with some features.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-33997

Medium priority
Needs evaluation

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user’s equation.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-33996

Medium priority
Needs evaluation

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

1 affected package

moodle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
moodle Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2024-5564

Medium priority
Fixed

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not...

1 affected package

libndp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libndp Fixed Fixed Fixed Fixed
Show less packages