Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.97% | — | Uninett MOD Auth Mellon | 22/8/2022 | 17/6/2026 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this… | |
| Modificada | Media (6.1) | 1.4% | — | MOD Auth Mellon Project MOD Auth MellonOracle ZFS Storage Appliance KITFedoraproject FedoraCanonical Ubuntu Linux | 29/6/2019 | 17/6/2026 | mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. | |
| Modificada | Media (6.1) | 2.1% | — | MOD Auth Mellon Project MOD Auth MellonFedoraproject FedoraRedhat Enterprise LinuxCanonical Ubuntu Linux | 27/3/2019 | 17/6/2026 | A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an… | |
| Modificada | Alta (8.1) | 3.0% | — | MOD Auth Mellon Project MOD Auth MellonFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+6 | 26/3/2019 | 17/6/2026 | A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based)… | |
| Modificada | Media (6.1) | 1.1% | — | Uninett MOD Auth Mellon | 13/3/2017 | 17/6/2026 | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site. | |
| Modificada | Alta (7.5) | 3.4% | — | Fedoraproject FedoraUninett MOD Auth Mellon | 15/4/2016 | 17/6/2026 | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data. | |
| Modificada | Alta (7.5) | 3.1% | — | Fedoraproject FedoraUninett MOD Auth Mellon | 15/4/2016 | 17/6/2026 | The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data. | |
| Modificada | Media (6.4) | 2.7% | — | Uninett MOD Auth MellonOracle Linux | 15/11/2014 | 17/6/2026 | The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory." | |
| Modificada | Alta (9.4) | 3.6% | — | Uninett MOD Auth MellonRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 14/11/2014 | 17/6/2026 | The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data. |