« Volver al listado

Entrouvert

Entrouvert Lasso: vulnerabilidades y CVE

Entrouvert Lasso tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-28156Alta (8.5)0.36%—13 ago 2026
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2025-47151Crítica (9.8)1.1%—5 nov 2025
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker…
CVE-2025-46784Alta (7.5)0.59%—5 nov 2025
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in…
CVE-2025-46705Alta (7.5)0.57%—5 nov 2025
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can…
CVE-2025-46404Alta (7.5)0.59%—5 nov 2025
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send…
CVE-2021-28091Alta (7.5)1.3%—4 jun 2021
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
CVE-2015-1783Alta (7.5)3.5%—11 ago 2017
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application…
CVE-2009-0050Media (4.3)1.3%—7 ene 2009
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1499.004 Application or System Exploitation3
  3. T1005 Data from Local System1
  4. T1059 Command and Scripting Interpreter1
  5. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.