Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.3) | 2.8% | — | Openldap | 7/9/2006 | 16/6/2026 | slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN). | |
| Modificada | Media (5) | 4.5% | — | Openldap | 1/6/2006 | 16/6/2026 | Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname. | |
| Modificada | Baja (2.6) | 8.2% | 💥 Exploit | Phpldapadmin Project PhpldapadminDebian Linux | 25/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e) delete_form.php; (2) scope parameter in (f)… | |
| Modificada | Alta (7.5) | 5.4% | — | Dave Carrigan Auth Ldap | 9/1/2006 | 16/6/2026 | Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username. | |
| Modificada | Alta (7.2) | 0.46% | — | Openldap | 21/12/2005 | 16/6/2026 | Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH. | |
| Modificada | Alta (10) | 1.5% | — | Ldapdiff | 22/11/2005 | 16/6/2026 | Unspecified vulnerability in ldapdiff before 1.1.1 has unknown impact and attack vectors, related to "ldapdiff.conf path construction". | |
| Modificada | Media (5) | 12% | 💥 Exploit | Phpldapadmin Project Phpldapadmin | 2/9/2005 | 16/6/2026 | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Phpldapadmin Project Phpldapadmin | 2/9/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Phpldapadmin Project Phpldapadmin | 30/8/2005 | 16/6/2026 | phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set. | |
| Modificada | Alta (7.5) | 3.6% | — | Padl Software PAM Ldap | 23/8/2005 | 16/6/2026 | Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate. | |
| Modificada | Media (5) | 2.8% | — | Padl NSS LdapPadl PAM Ldap | 30/6/2005 | 16/6/2026 | pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Netwin Surgeldap | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command. | |
| Modificada | Alta (7.5) | 8.4% | 💥 Exploit | Netwin Surgeldap | 31/12/2004 | 16/6/2026 | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter. | |
| Modificada | Media (5) | 1.8% | — | Openldap | 31/12/2004 | 16/6/2026 | Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.5) | 2.7% | — | OpenldapApple MAC OS XApple MAC OS X Server | 7/9/2004 | 16/6/2026 | OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without… | |
| Modificada | Media (6.8) | 1.1% | — | Pete Werner Login Ldap | 31/12/2003 | 16/6/2026 | login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password. | |
| Modificada | Alta (10) | 2.3% | — | Padl Software PAM Ldap | 20/10/2003 | 16/6/2026 | Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system. | |
| Modificada | Media (5) | 2.6% | — | Openldap | 20/3/2003 | 16/6/2026 | ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault). | |
| Modificada | Baja (1.2) | 0.34% | — | Openldap | 19/2/2003 | 16/6/2026 | slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests. | |
| Modificada | Alta (7.5) | 7.0% | — | Openldap | 2/1/2003 | 16/6/2026 | Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in… | |
| Modificada | Alta (7.5) | 2.9% | — | Openldap | 2/1/2003 | 16/6/2026 | OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges. | |
| Modificada | Alta (10) | 2.1% | — | Aldap | 31/12/2002 | 16/6/2026 | Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions. | |
| Modificada | Alta (10) | 4.1% | — | HP Ldap-ux IntegrationHp-ux | 31/12/2002 | 16/6/2026 | Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users. | |
| Modificada | Alta (7.5) | 2.9% | — | C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap | 12/8/2002 | 16/6/2026 | Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. | |
| Modificada | Alta (7.5) | 2.5% | — | Padl Software NSS Ldap | 12/8/2002 | 16/6/2026 | Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. |