Записи entrouvert
7 опубликованных записей вендора entrouvert.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-476 NULL Pointer Dereference1
- CWE-617 Reachable Assertion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2025-47151Эксплойта нет | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.entrouvert · lasso · CWE-843 | Критическая9,8 | — | 1,1 % | 5 нояб. 2025 г. |
31Наблюдать | CVE-2015-1783Эксплойта нет | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackersfedoraproject · fedora · CWE-119 | Высокая7,5 | — | 3,5 % | 11 авг. 2017 г. |
30Наблюдать | CVE-2021-28091Эксплойта нет | Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.entrouvert · lasso · CWE-347 | Высокая7,5 | — | 1,3 % | 4 июн. 2021 г. |
30Наблюдать | CVE-2025-46404Эксплойта нет | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1.entrouvert · lasso · CWE-476 | Высокая7,5 | — | 0,6 % | 5 нояб. 2025 г. |
30Наблюдать | CVE-2025-46784Эксплойта нет | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1.entrouvert · lasso · CWE-401 | Высокая7,5 | — | 0,6 % | 5 нояб. 2025 г. |
30Наблюдать | CVE-2025-46705Эксплойта нет | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.entrouvert · lasso · CWE-617 | Высокая7,5 | — | 0,6 % | 5 нояб. 2025 г. |
17Наблюдать | CVE-2009-0050Эксплойта нет | Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypaentrouvert · lasso · CWE-20 | Средняя4,3 | — | 1,3 % | 7 янв. 2009 г. |
- CVE-2025-4715139Наблюдать
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %entrouvert · lasso5 нояб. 2025 г.
- CVE-2015-178331Наблюдать
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %fedoraproject · fedora11 авг. 2017 г.
- CVE-2021-2809130Наблюдать
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %entrouvert · lasso4 июн. 2021 г.
- CVE-2025-4640430Наблюдать
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %entrouvert · lasso5 нояб. 2025 г.
- CVE-2025-4678430Наблюдать
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %entrouvert · lasso5 нояб. 2025 г.
- CVE-2025-4670530Наблюдать
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %entrouvert · lasso5 нояб. 2025 г.
- CVE-2009-005017Наблюдать
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypa
СредняяCVSS 4,3Эксплойта нетEPSS 1 %entrouvert · lasso7 янв. 2009 г.