Skip to content
Noroxi

Internet2 records

8 published records for vendor internet2.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
75%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2009-3476
    38Monitor

    Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before

    CriticalCVSS 9.3No exploitEPSS 4%

    internet2 · shibboleth-spSep 29, 2009

  • Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways.

    CriticalCVSS 9.1No exploitEPSS 0%

    Jun 29, 2024

  • CVE-2009-3474
    30Monitor

    OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow

    HighCVSS 7.5No exploitEPSS 2%

    internet2 · opensamlSep 29, 2009

  • CVE-2009-3475
    30Monitor

    Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly

    HighCVSS 7.5No exploitEPSS 1%

    internet2 · shibboleth-spSep 29, 2009

  • Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary we

    MediumCVSS 6.1No exploitEPSS 1%

    internet2 · grouperDec 3, 2018

  • CVE-2013-6440
    21Monitor

    The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set t

    MediumCVSS 5.0No exploitEPSS 3%

    shibboleth · opensamlFeb 14, 2014

  • In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

    MediumCVSS 4.9No exploitEPSS 0%

    internet2 · grouperSep 18, 2025

  • CVE-2009-3300
    11Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service

    LowCVSS 2.6No exploitEPSS 2%

    internet2 · identity providerNov 6, 2009