entrouvert kayıtları
entrouvert üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-476 NULL Pointer Dereference1
- CWE-617 Reachable Assertion1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-47151İstismar yok | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.entrouvert · lasso · CWE-843 | Kritik9,8 | — | %1,1 | 5 Kas 2025 |
31İzleyin | CVE-2015-1783İstismar yok | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackersfedoraproject · fedora · CWE-119 | Yüksek7,5 | — | %3,5 | 11 Ağu 2017 |
30İzleyin | CVE-2021-28091İstismar yok | Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.entrouvert · lasso · CWE-347 | Yüksek7,5 | — | %1,3 | 4 Haz 2021 |
30İzleyin | CVE-2025-46404İstismar yok | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1.entrouvert · lasso · CWE-476 | Yüksek7,5 | — | %0,6 | 5 Kas 2025 |
30İzleyin | CVE-2025-46784İstismar yok | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1.entrouvert · lasso · CWE-401 | Yüksek7,5 | — | %0,6 | 5 Kas 2025 |
30İzleyin | CVE-2025-46705İstismar yok | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.entrouvert · lasso · CWE-617 | Yüksek7,5 | — | %0,6 | 5 Kas 2025 |
17İzleyin | CVE-2009-0050İstismar yok | Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypaentrouvert · lasso · CWE-20 | Orta4,3 | — | %1,3 | 7 Oca 2009 |
- CVE-2025-4715139İzleyin
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.
KritikCVSS 9,8İstismar yokEPSS %1entrouvert · lasso5 Kas 2025
- CVE-2015-178331İzleyin
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers
YüksekCVSS 7,5İstismar yokEPSS %3fedoraproject · fedora11 Ağu 2017
- CVE-2021-2809130İzleyin
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
YüksekCVSS 7,5İstismar yokEPSS %1entrouvert · lasso4 Haz 2021
- CVE-2025-4640430İzleyin
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1.
YüksekCVSS 7,5İstismar yokEPSS %1entrouvert · lasso5 Kas 2025
- CVE-2025-4678430İzleyin
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1.
YüksekCVSS 7,5İstismar yokEPSS %1entrouvert · lasso5 Kas 2025
- CVE-2025-4670530İzleyin
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2.
YüksekCVSS 7,5İstismar yokEPSS %1entrouvert · lasso5 Kas 2025
- CVE-2009-005017İzleyin
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypa
OrtaCVSS 4,3İstismar yokEPSS %1entrouvert · lasso7 Oca 2009