Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 14% | 💥 Exploit | Openldap | 20/3/2011 | 16/6/2026 | modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field. | |
| Modificada | Media (6.8) | 3.9% | — | Openldap | 20/3/2011 | 16/6/2026 | bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password. | |
| Modificada | Media (4.6) | 2.6% | — | Openldap | 20/3/2011 | 16/6/2026 | chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server. | |
| Modificada | Media (6.8) | 1.5% | — | Arthurdejong Nss-pam-ldapd | 15/3/2011 | 16/6/2026 | nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication. | |
| Modificada | Alta (7.5) | 1.3% | — | Jens Vagelpohl Zope-ldapuserfolder | 20/8/2010 | 16/6/2026 | The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges. | |
| Modificada | Media (5) | 5.2% | — | Openldap | 28/7/2010 | 16/6/2026 | OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the… | |
| Modificada | Crítica (9.8) | 28% | 💥 Exploit | OpenldapVmware EsxiOpensuseApple MAC OS X+1 | 28/7/2010 | 16/6/2026 | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8… | |
| Modificada | Alta (7.5) | 10.0% | 💥 Exploit | Phpldapadmin Project Phpldapadmin | 28/12/2009 | 16/6/2026 | Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter. | |
| Modificada | Media (4.3) | 3.3% | — | OpenldapApple MAC OS XFedoraproject Fedora | 23/10/2009 | 16/6/2026 | libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted… | |
| Modificada | Media (5.5) | 1.1% | — | Debian Nss-ldapDebian Linux | 31/3/2009 | 16/6/2026 | nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field. | |
| Modificada | Baja (2.1) | 0.44% | — | Hpsi Acf2 ConnectorHpsi Active Directory ConnectorHpsi Bidir Dirx ConnectorHpsi Edirectory Connector+7 | 11/9/2008 | 16/6/2026 | Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1.02 and earlier, HPSI OID Connector 1.02 and earlier, HPSI IBM… | |
| Modificada | Alta (9) | 3.8% | — | Hpsi Active Directory Bidirectional Ldap Connector | 17/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Openldap | 1/7/2008 | 16/6/2026 | liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error. | |
| Modificada | Alta (7.2) | 0.52% | — | HP Ldap-ux | 8/5/2008 | 16/6/2026 | Unspecified vulnerability in HP LDAP-UX vB.04.10 through vB.04.15 allows local users to gain privileges via unknown vectors. | |
| Modificada | Media (4) | 3.1% | — | Openldap | 13/2/2008 | 16/6/2026 | slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698. | |
| Modificada | Media (4) | 2.0% | — | Openldap | 1/2/2008 | 16/6/2026 | The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability. | |
| Modificada | Media (4.3) | 1.2% | — | NSS Ldap | 13/11/2007 | 16/6/2026 | Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being… | |
| Modificada | Alta (7.1) | 2.6% | — | Openldap | 30/10/2007 | 16/6/2026 | slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow attackers to cause a denial of service (segmentation fault) via unknown vectors… | |
| Modificada | Alta (7.1) | 3.7% | — | Openldap | 30/10/2007 | 16/6/2026 | OpenLDAP before 2.3.39 allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute. NOTE: this has been reported as a double free, but the reports are inconsistent. | |
| Modificada | Baja (2.1) | 0.34% | — | Ldapscripts | 11/10/2007 | 16/6/2026 | ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepassword function. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Alpha Centauri Software Sidvault Ldap Server | 28/8/2007 | 16/6/2026 | Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind. | |
| Modificada | Alta (7.2) | 0.33% | — | Ldap Account Manager | 3/4/2007 | 16/6/2026 | Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program. | |
| Modificada | Media (4.3) | 1.3% | — | Ldap Account Manager | 3/4/2007 | 16/6/2026 | lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS). | |
| Modificada | Media (5.1) | 9.3% | 💥 Exploit | Openldap | 13/12/2006 | 16/6/2026 | Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long… | |
| Modificada | Alta (7.5) | 77% | — | OpenldapCanonical Ubuntu Linux | 7/11/2006 | 16/6/2026 | OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure. |