NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
10761  CVE-2011-4292  Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.    Medium  2017-01-07  2012-07-16  View
10762  CVE-2011-4293  The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.    6.4  Medium  2017-01-07  2012-07-16  View
10763  CVE-2011-4294  The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.    5.8  Medium  2017-01-07  2012-07-16  View
10764  CVE-2011-4295  The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.    6.5  Medium  2017-01-07  2012-07-16  View
10765  CVE-2011-4296  lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.    5.5  Medium  2017-01-07  2012-07-16  View

Page 2153 of 17672, showing 5 records out of 88360 total, starting on record 10761, ending on 10765

Actions