NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 47054 | CVE-2012-6106 | calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object. | 2 | 5.5 | Medium | 2017-01-19 | 2013-01-30 | View | |
| 37972 | CVE-2013-1829 | calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role. | 2 | 4 | Medium | 2017-01-18 | 2013-03-26 | View | |
| 18431 | CVE-2016-2156 | calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request. | 2 | 4 | Medium | 2017-01-19 | 2016-05-24 | View | |
| 22716 | CVE-2015-0215 | calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request. | 2 | 4 | Medium | 2017-01-19 | 2015-06-02 | View | |
| 66897 | CVE-2005-1148 | calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 15377 of 17672, showing 5 records out of 88360 total, starting on record 76881, ending on 76885