İçeriğe atla
Noroxi

uninett kayıtları

uninett üreticisine ait 9 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

9 kayıt
  • CVE-2014-8567
    38İzleyin

    The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout

    KritikCVSS 9,4İstismar yokEPSS %4

    uninett · mod auth mellon14 Kas 2014

  • CVE-2021-32642
    37İzleyin

    Missing input validation in dynamic discovery example scripts.

    KritikCVSS 9,4İstismar yokEPSS %1

    uninett · radsecproxy28 May 2021

  • CVE-2016-2146
    31İzleyin

    The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cau

    YüksekCVSS 7,5İstismar yokEPSS %3

    fedoraproject · fedora15 Nis 2016

  • CVE-2016-2145
    31İzleyin

    The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which a

    YüksekCVSS 7,5İstismar yokEPSS %3

    fedoraproject · fedora15 Nis 2016

  • CVE-2014-8566
    26İzleyin

    The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation f

    OrtaCVSS 6,4İstismar yokEPSS %3

    uninett · mod auth mellon15 Kas 2014

  • CVE-2012-4523
    26İzleyin

    radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to th

    OrtaCVSS 6,4İstismar yokEPSS %2

    uninett · radsecproxy19 Kas 2012

  • CVE-2012-4566
    25İzleyin

    The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that

    OrtaCVSS 6,4İstismar yokEPSS %1

    uninett · radsecproxy19 Kas 2012

  • CVE-2017-6807
    24İzleyin

    mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a s

    OrtaCVSS 6,1İstismar yokEPSS %1

    uninett · mod auth mellon13 Mar 2017

  • CVE-2021-3639
    24İzleyin

    A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly.

    OrtaCVSS 6,1İstismar yokEPSS %1

    uninett · mod auth mellon22 Ağu 2022