Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2012-4403 theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attack… Moodle Patch available Fix from $1,6002012-09-19 MEDIUM 5.0 CVE-2012-4407 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files,… Moodle Patch available Fix from $1,6002012-09-19 MEDIUM 6.5 CVE-2012-3395 SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote auth… Moodle Mitigation only Fix from $1,6002012-07-23 MEDIUM 5.5 CVE-2012-3392 mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote a… Moodle Mitigation only Fix from $1,6002012-07-23 MEDIUM 5.0 CVE-2012-3394 auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an h… Moodle Mitigation only Fix from $1,6002012-07-23 MEDIUM 6.5 CVE-2012-2359 admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privilege… Moodle Mitigation only Fix from $1,6002012-07-21 MEDIUM 6.5 CVE-2012-2363 SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to e… Moodle Mitigation only Fix from $1,6002012-07-21 MEDIUM 5.5 CVE-2012-2366 mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated… Moodle Mitigation only Fix from $1,6002012-07-21 MEDIUM 5.5 CVE-2012-2358 Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and m… Moodle Mitigation only Fix from $1,6002012-07-21 MEDIUM 5.0 CVE-2012-2357 The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and… Moodle Mitigation only Fix from $1,6002012-07-21 MEDIUM 5.5 CVE-2011-4589 backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege… Moodle Patch available Fix from $1,6002012-07-20 MEDIUM 5.0 CVE-2011-4588 The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass i… Moodle Mitigation only Fix from $1,6002012-07-20 MEDIUM 5.0 CVE-2011-4592 The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might all… Moodle Mitigation only Fix from $1,6002012-07-20 MEDIUM 6.8 CVE-2011-4587 lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the passw… Moodle Mitigation only Fix from $1,6002012-07-20 MEDIUM 6.5 CVE-2011-4583 Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have a… Moodle Patch available Fix from $1,6002012-07-20 MEDIUM 5.0 CVE-2011-4585 login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, whi… Moodle Mitigation only Fix from $1,6002012-07-20 MEDIUM 5.0 CVE-2011-4586 CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 … Moodle Mitigation only Fix from $1,6002012-07-20 HIGH 7.5 CVE-2012-0801 lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspeci… Moodle Mitigation only Fix from $1,9502012-07-17 MEDIUM 6.5 CVE-2012-0795 Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows re… Moodle Mitigation only Fix from $1,6002012-07-17 MEDIUM 5.5 CVE-2012-0797 The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass th… Moodle after 2.1.3 Fix from $1,6002012-07-17 MEDIUM 5.5 CVE-2012-0798 The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by … Moodle Mitigation only Fix from $1,6002012-07-17 MEDIUM 5.0 CVE-2012-0793 Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbi… Moodle Mitigation only Fix from $1,6002012-07-17 MEDIUM 5.0 CVE-2012-0794 The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a har… Moodle Mitigation only Fix from $1,6002012-07-17 MEDIUM 6.5 CVE-2011-4295 The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authoriz… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 6.4 CVE-2011-4293 The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScrip… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 6.4 CVE-2011-4297 comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.8 CVE-2011-4294 The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link re… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 5.5 CVE-2011-4296 lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote … Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 6.8 CVE-2011-4133 Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified vic… Moodle Mitigation only Fix from $1,6002012-07-16 MEDIUM 6.8 CVE-2011-4281 Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitr… Moodle Mitigation only Fix from $1,6002012-07-16