Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.9% | — | Ldap / SSO Authentication Project Ldap / SSO Authentication | 28/8/2017 | 17/6/2026 | Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3. | |
| Modificada | Media (4.7) | 0.15% | — | Openldap-servers | 17/7/2017 | 17/6/2026 | /usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Phpldapadmin Project PhpldapadminDebian Linux | 8/7/2017 | 17/6/2026 | phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter. | |
| Modificada | Media (6.5) | 7.2% | — | OpenldapDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+6 | 29/5/2017 | 17/6/2026 | servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0. | |
| Modificada | Alta (7.5) | 5.7% | — | Apache Groovy Ldap | 18/1/2017 | 17/6/2026 | main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods. | |
| Modificada | Alta (7.8) | 2.1% | — | Apache Ldap StudioApache Directory Studio | 11/4/2016 | 17/6/2026 | The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet. | |
| Modificada | Alta (7.5) | 5.3% | — | OpenldapOracle LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 7/12/2015 | 17/6/2026 | The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (5) | 20% | 💥 Exploit | OpenldapApple MAC OS X | 11/9/2015 | 17/6/2026 | The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. | |
| Modificada | Media (4) | 1.9% | — | OpenldapDebian Linux | 1/4/2015 | 17/6/2026 | The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors. | |
| Modificada | Media (5) | 3.4% | — | OpenldapOpensuseApple MAC OS X | 12/2/2015 | 17/6/2026 | Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control. | |
| Modificada | Media (5) | 11% | — | Openldap | 12/2/2015 | 17/6/2026 | The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request. | |
| Modificada | Media (4) | 1.1% | — | Ldap Project Ldap | 11/9/2014 | 17/6/2026 | Unspecified vulnerability in the LDAP (eu_ldap) extension before 2.8.18 for TYPO3 allows remote authenticated users to obtain sensitive information via unknown vectors. | |
| Modificada | Media (4.3) | 2.3% | — | Martin Nagy Bind-dyndb-ldap | 26/2/2014 | 16/6/2026 | The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP query errors, which allows remote attackers to cause a denial of service (infinite loop and named server hang) via a non-alphabet character in the base DN in an LDAP search DNS query. | |
| Modificada | Media (4.3) | 11% | — | Debian LinuxOpenldap | 5/2/2014 | 16/6/2026 | The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search. | |
| Modificada | Media (4.3) | 1.8% | — | Web2ldap | 3/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "displaying group DN and entry data in group administration UI." | |
| Modificada | Media (4.3) | 1.4% | — | Ldap-account-manager Ldap Account Manager | 5/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter. | |
| Modificada | Media (6.8) | 3.6% | — | Arthurdejong Nss-pam-ldapd | 5/3/2013 | 16/6/2026 | nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to… | |
| Modificada | Alta (7.5) | 1.6% | — | Lemonldap-ng Lemonldap\ | 1/1/2013 | 16/6/2026 | LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data. | |
| Modificada | Media (5) | 3.1% | — | Martin Nagy Bind-dyndb-ldap | 7/8/2012 | 16/6/2026 | The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query. | |
| Modificada | Baja (2.6) | 3.6% | — | Openldap | 29/6/2012 | 16/6/2026 | slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned. | |
| Modificada | Media (4.3) | 4.0% | — | Openldap | 17/6/2012 | 16/6/2026 | libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Phpldapadmin Project Phpldapadmin | 11/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php. | |
| Modificada | Alta (7.5) | 52% | 💥 Exploit | Phpldapadmin Project Phpldapadmin | 2/11/2011 | 16/6/2026 | The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011. | |
| Modificada | Media (4.3) | 5.4% | 💥 Exploit | Phpldapadmin Project Phpldapadmin | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command. | |
| Modificada | Media (4) | 3.3% | — | Openldap | 27/10/2011 | 16/6/2026 | Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry. |