İçeriğe atla
Noroxi

simplesamlphp kayıtları

simplesamlphp üreticisine ait 35 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%97,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

35 kayıt
  • CVE-2018-6521
    40Planlayın

    The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte char

    KritikCVSS 9,8İstismar yokEPSS %3

    simplesamlphp · simplesamlphp1 Şub 2018

  • CVE-2017-12868
    40Planlayın

    The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta

    KritikCVSS 9,8İstismar yokEPSS %2

    simplesamlphp · simplesamlphp1 Eyl 2017

  • CVE-2017-12873
    39İzleyin

    SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth

    KritikCVSS 9,8İstismar yokEPSS %2

    simplesamlphp · simplesamlphp1 Eyl 2017

  • CVE-2016-9814
    37İzleyin

    The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x b

    KritikCVSS 9,1İstismar yokEPSS %2

    simplesamlphp · simplesamlphp16 Şub 2017

  • CVE-2019-3465
    36İzleyin

    Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic

    YüksekCVSS 8,8İstismar yokEPSS %3

    simplesamlphp · simplesamlphp7 Kas 2019

  • CVE-2024-52596
    35İzleyin

    SimpleSAMLphp xml-common XXE vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    simplesamlphp · xml-common2 Ara 2024

  • CVE-2024-52806
    33İzleyin

    SimpleSAMLphp SAML2 has an XXE in parsing SAML messages

    YüksekCVSS 8,3Kavram kanıtıEPSS %0

    simplesamlphp · saml22 Ara 2024

  • CVE-2018-7711
    32İzleyin

    HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation uti

    YüksekCVSS 8,1İstismar yokEPSS %1

    simplesamlphp · simplesamlphp5 Mar 2018

  • CVE-2017-18122
    32İzleyin

    A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16.

    YüksekCVSS 8,1İstismar yokEPSS %1

    simplesamlphp · simplesamlphp2 Şub 2018

  • CVE-2026-32600
    32İzleyin

    xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption

    YüksekCVSS 8,2İstismar yokEPSS %0

    simplesamlphp · xml-security16 Mar 2026

  • CVE-2017-12869
    31İzleyin

    The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an a

    YüksekCVSS 7,5İstismar yokEPSS %2

    simplesamlphp · simplesamlphp1 Eyl 2017

  • CVE-2018-6519
    31İzleyin

    The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerab

    YüksekCVSS 7,5İstismar yokEPSS %2

    simplesamlphp · saml21 Şub 2018

  • CVE-2017-12874
    30İzleyin

    The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signat

    YüksekCVSS 7,5İstismar yokEPSS %1

    simplesamlphp · infocard module1 Eyl 2017

  • CVE-2018-7644
    30İzleyin

    The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allow

    YüksekCVSS 7,5İstismar yokEPSS %1

    simplesamlphp · simplesamlphp5 Mar 2018

  • CVE-2011-4625
    30İzleyin

    simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt

    YüksekCVSS 7,5İstismar yokEPSS %1

    simplesamlphp · simplesamlphp6 Kas 2019

  • CVE-2023-49087
    30İzleyin

    Validation of SignedInfo

    YüksekCVSS 7,5İstismar yokEPSS %0

    simplesamlphp · saml230 Kas 2023

  • CVE-2026-49284
    28İzleyin

    SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmatio

    YüksekCVSS 7,1İstismar yokEPSS %0

    simplesamlphp · simplesamlphp17 Tem 2026

  • CVE-2016-9955
    25İzleyin

    The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 re

    OrtaCVSS 6,3İstismar yokEPSS %1

    simplesamlphp · simplesamlphp16 Şub 2017

  • CVE-2017-18121
    24İzleyin

    The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links

    OrtaCVSS 6,1İstismar yokEPSS %1

    simplesamlphp · simplesamlphp2 Şub 2018

  • CVE-2018-6520
    24İzleyin

    SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.

    OrtaCVSS 6,1İstismar yokEPSS %1

    simplesamlphp · simplesamlphp1 Şub 2018

  • CVE-2010-10002
    24İzleyin

    SimpleSAMLphp simplesamlphp-module-openid OpenID consumer.php cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    simplesamlphp · simplesamlphp-module-openid1 Oca 2023

  • CVE-2010-10004
    24İzleyin

    Information Cards Module cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    simplesamlphp · information cards module9 Oca 2023

  • CVE-2025-65954
    24İzleyin

    SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

    OrtaCVSS 6,1İstismar yokEPSS %0

    simplesamlphp · simplesamlphp-module-casserver18 May 2026

  • CVE-2017-12872
    23İzleyin

    The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow r

    OrtaCVSS 5,9İstismar yokEPSS %1

    simplesamlphp · simplesamlphp1 Eyl 2017

  • CVE-2017-12867
    23İzleyin

    The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its

    OrtaCVSS 5,9İstismar yokEPSS %1

    simplesamlphp · simplesamlphp29 Ağu 2017