uninett kayıtları
uninett üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-399 Resource Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2014-8567İstismar yok | The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logoutuninett · mod auth mellon · CWE-399 | Kritik9,4 | — | %3,6 | 14 Kas 2014 |
37İzleyin | CVE-2021-32642İstismar yok | Missing input validation in dynamic discovery example scripts.uninett · radsecproxy · CWE-20 | Kritik9,4 | — | %1,3 | 28 May 2021 |
31İzleyin | CVE-2016-2146İstismar yok | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to caufedoraproject · fedora · CWE-119 | Yüksek7,5 | — | %3,4 | 15 Nis 2016 |
31İzleyin | CVE-2016-2145İstismar yok | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which afedoraproject · fedora · CWE-20 | Yüksek7,5 | — | %3,1 | 15 Nis 2016 |
26İzleyin | CVE-2014-8566İstismar yok | The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation funinett · mod auth mellon · CWE-200 | Orta6,4 | — | %2,7 | 15 Kas 2014 |
26İzleyin | CVE-2012-4523İstismar yok | radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to thuninett · radsecproxy · CWE-264 | Orta6,4 | — | %1,8 | 19 Kas 2012 |
25İzleyin | CVE-2012-4566İstismar yok | The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings thatuninett · radsecproxy · CWE-264 | Orta6,4 | — | %1,5 | 19 Kas 2012 |
24İzleyin | CVE-2017-6807İstismar yok | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a suninett · mod auth mellon · CWE-79 | Orta6,1 | — | %1,1 | 13 Mar 2017 |
24İzleyin | CVE-2021-3639İstismar yok | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.uninett · mod auth mellon · CWE-601 | Orta6,1 | — | %1,0 | 22 Ağu 2022 |
- CVE-2014-856738İzleyin
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout
KritikCVSS 9,4İstismar yokEPSS %4uninett · mod auth mellon14 Kas 2014
- CVE-2021-3264237İzleyin
Missing input validation in dynamic discovery example scripts.
KritikCVSS 9,4İstismar yokEPSS %1uninett · radsecproxy28 May 2021
- CVE-2016-214631İzleyin
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cau
YüksekCVSS 7,5İstismar yokEPSS %3fedoraproject · fedora15 Nis 2016
- CVE-2016-214531İzleyin
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which a
YüksekCVSS 7,5İstismar yokEPSS %3fedoraproject · fedora15 Nis 2016
- CVE-2014-856626İzleyin
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation f
OrtaCVSS 6,4İstismar yokEPSS %3uninett · mod auth mellon15 Kas 2014
- CVE-2012-452326İzleyin
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to th
OrtaCVSS 6,4İstismar yokEPSS %2uninett · radsecproxy19 Kas 2012
- CVE-2012-456625İzleyin
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that
OrtaCVSS 6,4İstismar yokEPSS %1uninett · radsecproxy19 Kas 2012
- CVE-2017-680724İzleyin
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a s
OrtaCVSS 6,1İstismar yokEPSS %1uninett · mod auth mellon13 Mar 2017
- CVE-2021-363924İzleyin
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.
OrtaCVSS 6,1İstismar yokEPSS %1uninett · mod auth mellon22 Ağu 2022