Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.8% | — | Fedoraproject 389 Directory ServerRedhat Directory Server | 31/7/2013 | 16/6/2026 | The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute. | |
| Modificada | Media (5) | 2.2% | — | IBM Rational Directory Server | 28/5/2013 | 16/6/2026 | IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code. | |
| Modificada | Baja (2.6) | 2.1% | — | Fedoraproject 389 Directory Server | 13/5/2013 | 16/6/2026 | The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain… | |
| Modificada | Media (5) | 2.7% | — | Fedoraproject 389 Directory Server | 13/3/2013 | 16/6/2026 | 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence. | |
| Modificada | Media (6) | 1.9% | — | Fedoraproject 389 Directory Server | 1/10/2012 | 16/6/2026 | 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Global Security KITIBM Rational Directory ServerIBM Tivoli Directory Server | 8/8/2012 | 16/6/2026 | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving… | |
| Modificada | Media (5) | 3.9% | — | IBM Global Security KITIBM Rational Directory ServerIBM Tivoli Directory Server | 8/8/2012 | 16/6/2026 | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of… | |
| Modificada | Baja (2.1) | 1.3% | — | Redhat Directory ServerFedoraproject 389 Directory Server | 3/7/2012 | 16/6/2026 | 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password. | |
| Modificada | Baja (1.2) | 0.64% | — | Redhat Directory ServerFedoraproject 389 Directory Server | 3/7/2012 | 16/6/2026 | 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute. | |
| Modificada | Baja (2.3) | 0.90% | — | Fedoraproject 389 Directory Server | 3/7/2012 | 16/6/2026 | The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and… | |
| Modificada | Media (5) | 1.7% | — | IBM Tivoli Directory Server | 22/4/2012 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request. | |
| Modificada | Media (4.3) | 1.9% | — | IBM Tivoli Directory Server | 22/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 2.3% | — | IBM Tivoli Directory Server | 22/4/2012 | 16/6/2026 | The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol. | |
| Modificada | Media (5) | 1.3% | — | IBM Tivoli Directory Server | 17/7/2011 | 16/6/2026 | The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | |
| Modificada | Media (5) | 2.1% | — | IBM Tivoli Directory Server | 17/7/2011 | 16/6/2026 | IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL. | |
| Modificada | Baja (2.1) | 0.29% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log. | |
| Modificada | Media (4) | 0.88% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search. | |
| Modificada | Baja (1.7) | 0.35% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the… | |
| Modificada | Alta (10) | 16% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka… | |
| Modificada | Media (4) | 1.1% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is… | |
| Modificada | Media (4) | 0.88% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform certain locking of linked-list access, which allows remote authenticated users to cause a denial of service (daemon crash) via a paged search. | |
| Modificada | Media (4) | 0.88% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing. | |
| Modificada | Media (4) | 0.88% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an improper ibm-slapdIdleTimeOut configuration setting. | |
| Modificada | Media (4) | 1.3% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the… | |
| Modificada | Media (4) | 0.88% | — | IBM Tivoli Directory Server | 21/4/2011 | 16/6/2026 | IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry. |