entrouvert records
7 published records for vendor entrouvert.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-476 NULL Pointer Dereference1
- CWE-617 Reachable Assertion1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-47151No exploit | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.entrouvert · lasso · CWE-843 | Critical9.8 | — | 1.1% | Nov 5, 2025 |
31Monitor | CVE-2015-1783No exploit | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackersfedoraproject · fedora · CWE-119 | High7.5 | — | 3.5% | Aug 11, 2017 |
30Monitor | CVE-2021-28091No exploit | Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.entrouvert · lasso · CWE-347 | High7.5 | — | 1.3% | Jun 4, 2021 |
30Monitor | CVE-2025-46404No exploit | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1.entrouvert · lasso · CWE-476 | High7.5 | — | 0.6% | Nov 5, 2025 |
30Monitor | CVE-2025-46784No exploit | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1.entrouvert · lasso · CWE-401 | High7.5 | — | 0.6% | Nov 5, 2025 |
30Monitor | CVE-2025-46705No exploit | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.entrouvert · lasso · CWE-617 | High7.5 | — | 0.6% | Nov 5, 2025 |
17Monitor | CVE-2009-0050No exploit | Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypaentrouvert · lasso · CWE-20 | Medium4.3 | — | 1.3% | Jan 7, 2009 |
- CVE-2025-4715139Monitor
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.
CriticalCVSS 9.8No exploitEPSS 1%entrouvert · lassoNov 5, 2025
- CVE-2015-178331Monitor
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers
HighCVSS 7.5No exploitEPSS 3%fedoraproject · fedoraAug 11, 2017
- CVE-2021-2809130Monitor
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
HighCVSS 7.5No exploitEPSS 1%entrouvert · lassoJun 4, 2021
- CVE-2025-4640430Monitor
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1.
HighCVSS 7.5No exploitEPSS 1%entrouvert · lassoNov 5, 2025
- CVE-2025-4678430Monitor
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1.
HighCVSS 7.5No exploitEPSS 1%entrouvert · lassoNov 5, 2025
- CVE-2025-4670530Monitor
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.
HighCVSS 7.5No exploitEPSS 1%entrouvert · lassoNov 5, 2025
- CVE-2009-005017Monitor
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypa
MediumCVSS 4.3No exploitEPSS 1%entrouvert · lassoJan 7, 2009