VYPR
Vendor

Glewlwyd

Products
2
CVEs
6
Across products
7
Status
Private

Products

2

Recent CVEs

6
  • CVE-2024-25715MedFeb 11, 2024
    risk 0.00cvss 6.1epss 0.00

    Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.

  • CVE-2023-49208CriNov 23, 2023
    risk 0.00cvss 9.8epss 0.01

    scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.

  • CVE-2022-29967HigApr 29, 2022
    risk 0.00cvss 7.5epss 0.02

    static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.

  • CVE-2022-27240CriMar 18, 2022
    risk 0.00cvss 9.8epss 0.02

    scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.

  • CVE-2021-45379HigDec 30, 2021
    risk 0.00cvss 8.8epss 0.01

    Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.

  • CVE-2021-40818CriSep 8, 2021
    risk 0.00cvss 9.8epss 0.01

    scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.