CVE-2021-3639
- EPSS 0.12%
- Veröffentlicht 22.08.2022 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:22:02
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external an...
CVE-2017-6807
- EPSS 0.36%
- Veröffentlicht 13.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.
CVE-2016-2146
- EPSS 0.65%
- Veröffentlicht 15.04.2016 14:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount o...
CVE-2016-2145
- EPSS 0.8%
- Veröffentlicht 15.04.2016 14:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST ...
CVE-2014-8566
- EPSS 1.09%
- Veröffentlicht 15.11.2014 21:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
CVE-2014-8567
- EPSS 4.43%
- Veröffentlicht 14.11.2014 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.