Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.97%—Uninett MOD Auth Mellon22/8/202217/6/2026
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this…
ModificadaMedia (6.1)1.4%—MOD Auth Mellon Project MOD Auth MellonOracle ZFS Storage Appliance KITFedoraproject FedoraCanonical Ubuntu Linux29/6/201917/6/2026
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
ModificadaMedia (6.1)2.1%—MOD Auth Mellon Project MOD Auth MellonFedoraproject FedoraRedhat Enterprise LinuxCanonical Ubuntu Linux27/3/201917/6/2026
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an…
ModificadaAlta (8.1)3.0%—MOD Auth Mellon Project MOD Auth MellonFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+626/3/201917/6/2026
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based)…
ModificadaMedia (6.1)1.1%—Uninett MOD Auth Mellon13/3/201717/6/2026
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
ModificadaAlta (7.5)3.4%—Fedoraproject FedoraUninett MOD Auth Mellon15/4/201617/6/2026
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
ModificadaAlta (7.5)3.1%—Fedoraproject FedoraUninett MOD Auth Mellon15/4/201617/6/2026
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.
ModificadaMedia (6.4)2.7%—Uninett MOD Auth MellonOracle Linux15/11/201417/6/2026
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
ModificadaAlta (9.4)3.6%—Uninett MOD Auth MellonRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+314/11/201417/6/2026
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.