CVE-2025-47151
- EPSS 0.13%
- Veröffentlicht 05.11.2025 14:57:01
- Zuletzt bearbeitet 07.11.2025 19:53:04
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML respon...
CVE-2025-46404
- EPSS 0.09%
- Veröffentlicht 05.11.2025 14:56:59
- Zuletzt bearbeitet 07.11.2025 18:12:18
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to tr...
CVE-2025-46784
- EPSS 0.07%
- Veröffentlicht 05.11.2025 14:56:57
- Zuletzt bearbeitet 07.11.2025 20:01:13
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can s...
CVE-2025-46705
- EPSS 0.07%
- Veröffentlicht 05.11.2025 14:56:55
- Zuletzt bearbeitet 07.11.2025 20:02:36
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response t...
CVE-2021-28091
- EPSS 0.51%
- Veröffentlicht 04.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:59:04
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
CVE-2015-1783
- EPSS 1.06%
- Veröffentlicht 11.08.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
CVE-2009-0050
- EPSS 0.15%
- Veröffentlicht 07.01.2009 18:30:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-...