Uninett mod_auth_mellon 0.6.1

CPE Details

Uninett mod_auth_mellon 0.6.1
0.6.1
2019-07-02
14h45 +00:00
2019-07-02
14h45 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:uninett:mod_auth_mellon:0.6.1:*:*:*:*:*:*:*

Informations

Vendor

uninett

Product

mod_auth_mellon

Version

0.6.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-3639 2022-08-22 12h49 +00:00 A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.
6.1
Moyen
CVE-2017-6807 2017-03-13 13h00 +00:00 mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
6.1
Moyen
CVE-2016-2145 2016-04-15 12h00 +00:00 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.
7.5
Haute
CVE-2016-2146 2016-04-15 12h00 +00:00 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
7.5
Haute
CVE-2014-8566 2014-11-15 20h00 +00:00 The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
6.4
CVE-2014-8567 2014-11-14 14h00 +00:00 The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
9.4