Записи uninett
9 опубликованных записей вендора uninett.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-399 Resource Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2014-8567Эксплойта нет | The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logoutuninett · mod auth mellon · CWE-399 | Критическая9,4 | — | 3,6 % | 14 нояб. 2014 г. |
37Наблюдать | CVE-2021-32642Эксплойта нет | Missing input validation in dynamic discovery example scripts.uninett · radsecproxy · CWE-20 | Критическая9,4 | — | 1,3 % | 28 мая 2021 г. |
31Наблюдать | CVE-2016-2146Эксплойта нет | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to caufedoraproject · fedora · CWE-119 | Высокая7,5 | — | 3,4 % | 15 апр. 2016 г. |
31Наблюдать | CVE-2016-2145Эксплойта нет | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which afedoraproject · fedora · CWE-20 | Высокая7,5 | — | 3,1 % | 15 апр. 2016 г. |
26Наблюдать | CVE-2014-8566Эксплойта нет | The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation funinett · mod auth mellon · CWE-200 | Средняя6,4 | — | 2,7 % | 15 нояб. 2014 г. |
26Наблюдать | CVE-2012-4523Эксплойта нет | radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to thuninett · radsecproxy · CWE-264 | Средняя6,4 | — | 1,8 % | 19 нояб. 2012 г. |
25Наблюдать | CVE-2012-4566Эксплойта нет | The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings thatuninett · radsecproxy · CWE-264 | Средняя6,4 | — | 1,5 % | 19 нояб. 2012 г. |
24Наблюдать | CVE-2017-6807Эксплойта нет | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a suninett · mod auth mellon · CWE-79 | Средняя6,1 | — | 1,1 % | 13 мар. 2017 г. |
24Наблюдать | CVE-2021-3639Эксплойта нет | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.uninett · mod auth mellon · CWE-601 | Средняя6,1 | — | 1,0 % | 22 авг. 2022 г. |
- CVE-2014-856738Наблюдать
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout
КритическаяCVSS 9,4Эксплойта нетEPSS 4 %uninett · mod auth mellon14 нояб. 2014 г.
- CVE-2021-3264237Наблюдать
Missing input validation in dynamic discovery example scripts.
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %uninett · radsecproxy28 мая 2021 г.
- CVE-2016-214631Наблюдать
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cau
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %fedoraproject · fedora15 апр. 2016 г.
- CVE-2016-214531Наблюдать
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %fedoraproject · fedora15 апр. 2016 г.
- CVE-2014-856626Наблюдать
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation f
СредняяCVSS 6,4Эксплойта нетEPSS 3 %uninett · mod auth mellon15 нояб. 2014 г.
- CVE-2012-452326Наблюдать
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to th
СредняяCVSS 6,4Эксплойта нетEPSS 2 %uninett · radsecproxy19 нояб. 2012 г.
- CVE-2012-456625Наблюдать
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that
СредняяCVSS 6,4Эксплойта нетEPSS 1 %uninett · radsecproxy19 нояб. 2012 г.
- CVE-2017-680724Наблюдать
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a s
СредняяCVSS 6,1Эксплойта нетEPSS 1 %uninett · mod auth mellon13 мар. 2017 г.
- CVE-2021-363924Наблюдать
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %uninett · mod auth mellon22 авг. 2022 г.