Vulnerability Database

314,486

Total vulnerabilities in the database

CVE-2016-9955

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

CVSS v2:

  • Severity: Low
  • Score: 4
  • AV:N/AC:H/Au:N/C:N/I:P/A:P

CWEs: