Vulnerabilities > Simplesamlphp > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-12867 Insufficient Session Expiration vulnerability in Simplesamlphp
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.
network
high complexity
simplesamlphp CWE-613
5.9
2017-02-17 CVE-2016-9955 Improper Input Validation vulnerability in multiple products
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
local
high complexity
simplesamlphp debian CWE-20
6.3
2017-02-07 CVE-2016-3124 Information Exposure vulnerability in Simplesamlphp
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
network
low complexity
simplesamlphp CWE-200
5.3