Skip to content
Noroxi

uninett records

9 published records for vendor uninett.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

9 records
  • CVE-2014-8567
    38Monitor

    The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout

    CriticalCVSS 9.4No exploitEPSS 4%

    uninett · mod auth mellonNov 14, 2014

  • Missing input validation in dynamic discovery example scripts.

    CriticalCVSS 9.4No exploitEPSS 1%

    uninett · radsecproxyMay 28, 2021

  • CVE-2016-2146
    31Monitor

    The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cau

    HighCVSS 7.5No exploitEPSS 3%

    fedoraproject · fedoraApr 15, 2016

  • CVE-2016-2145
    31Monitor

    The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which a

    HighCVSS 7.5No exploitEPSS 3%

    fedoraproject · fedoraApr 15, 2016

  • CVE-2014-8566
    26Monitor

    The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation f

    MediumCVSS 6.4No exploitEPSS 3%

    uninett · mod auth mellonNov 15, 2014

  • CVE-2012-4523
    26Monitor

    radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to th

    MediumCVSS 6.4No exploitEPSS 2%

    uninett · radsecproxyNov 19, 2012

  • CVE-2012-4566
    25Monitor

    The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that

    MediumCVSS 6.4No exploitEPSS 1%

    uninett · radsecproxyNov 19, 2012

  • CVE-2017-6807
    24Monitor

    mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a s

    MediumCVSS 6.1No exploitEPSS 1%

    uninett · mod auth mellonMar 13, 2017

  • CVE-2021-3639
    24Monitor

    A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.

    MediumCVSS 6.1No exploitEPSS 1%

    uninett · mod auth mellonAug 22, 2022