NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10765 | CVE-2011-4296 | lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role. | 2 | 5.5 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10764 | CVE-2011-4295 | The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment. | 2 | 6.5 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10763 | CVE-2011-4294 | The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10762 | CVE-2011-4293 | The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors. | 2 | 6.4 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10761 | CVE-2011-4292 | Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations. | 2 | 4 | Medium | 2017-01-07 | 2012-07-16 | View |
Page 15520 of 17672, showing 5 records out of 88360 total, starting on record 77596, ending on 77600