uninett records
9 published records for vendor uninett.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-399 Resource Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2014-8567No exploit | The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logoutuninett · mod auth mellon · CWE-399 | Critical9.4 | — | 3.6% | Nov 14, 2014 |
37Monitor | CVE-2021-32642No exploit | Missing input validation in dynamic discovery example scripts.uninett · radsecproxy · CWE-20 | Critical9.4 | — | 1.3% | May 28, 2021 |
31Monitor | CVE-2016-2146No exploit | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to caufedoraproject · fedora · CWE-119 | High7.5 | — | 3.4% | Apr 15, 2016 |
31Monitor | CVE-2016-2145No exploit | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which afedoraproject · fedora · CWE-20 | High7.5 | — | 3.1% | Apr 15, 2016 |
26Monitor | CVE-2014-8566No exploit | The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation funinett · mod auth mellon · CWE-200 | Medium6.4 | — | 2.7% | Nov 15, 2014 |
26Monitor | CVE-2012-4523No exploit | radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to thuninett · radsecproxy · CWE-264 | Medium6.4 | — | 1.8% | Nov 19, 2012 |
25Monitor | CVE-2012-4566No exploit | The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings thatuninett · radsecproxy · CWE-264 | Medium6.4 | — | 1.5% | Nov 19, 2012 |
24Monitor | CVE-2017-6807No exploit | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a suninett · mod auth mellon · CWE-79 | Medium6.1 | — | 1.1% | Mar 13, 2017 |
24Monitor | CVE-2021-3639No exploit | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.uninett · mod auth mellon · CWE-601 | Medium6.1 | — | 1.0% | Aug 22, 2022 |
- CVE-2014-856738Monitor
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout
CriticalCVSS 9.4No exploitEPSS 4%uninett · mod auth mellonNov 14, 2014
- CVE-2021-3264237Monitor
Missing input validation in dynamic discovery example scripts.
CriticalCVSS 9.4No exploitEPSS 1%uninett · radsecproxyMay 28, 2021
- CVE-2016-214631Monitor
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cau
HighCVSS 7.5No exploitEPSS 3%fedoraproject · fedoraApr 15, 2016
- CVE-2016-214531Monitor
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which a
HighCVSS 7.5No exploitEPSS 3%fedoraproject · fedoraApr 15, 2016
- CVE-2014-856626Monitor
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation f
MediumCVSS 6.4No exploitEPSS 3%uninett · mod auth mellonNov 15, 2014
- CVE-2012-452326Monitor
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to th
MediumCVSS 6.4No exploitEPSS 2%uninett · radsecproxyNov 19, 2012
- CVE-2012-456625Monitor
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that
MediumCVSS 6.4No exploitEPSS 1%uninett · radsecproxyNov 19, 2012
- CVE-2017-680724Monitor
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a s
MediumCVSS 6.1No exploitEPSS 1%uninett · mod auth mellonMar 13, 2017
- CVE-2021-363924Monitor
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.
MediumCVSS 6.1No exploitEPSS 1%uninett · mod auth mellonAug 22, 2022