CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also...Show more |
2Debian Simplesamlphp3Debian Linux Saml2SimplesamlphpJun 17, 2026 Mar 5, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forc...Show more |
2Debian Simplesamlphp2Debian Linux Saml2Jun 17, 2026 Feb 2, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp. |
1Simplesamlphp 2Saml2 SimplesamlphpMay 13, 2026 Feb 17, 2017 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML respons...Show more |