Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9)0.38%—389project 389 DS BaseAI1/10/20262/10/2026
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's…
Pendiente de análisisAlta (7.5)0.35%—Port389 389-ds-baseAI1/10/20262/10/2026
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker…
Pendiente de análisisAlta (8.4)0.48%—389 Project 389 DS BaseAICockpit 389 ConsoleAI7/9/20268/9/2026
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN…
Pendiente de análisisMedia (6.5)0.78%—389 Project 389 DS BaseAI25/8/20268/9/2026
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for…
Pendiente de análisisMedia (5.9)0.51%—389 Project 389 DS BaseAI12/8/202614/8/2026
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote…
Pendiente de análisisMedia (5.3)0.40%—389 Project 389 DS BaseAI22/7/202622/7/2026
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.
AplazadaAlta (7.2)1.2%—389 Project 389 DS BaseAI23/2/202630/6/2026
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters.…
AplazadaMedia (4.9)0.59%—389 Project 389 DS BaseAI18/3/202530/6/2026
A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial…
AplazadaMedia (5.7)0.42%—389 Project 389 DS BaseAI5/9/202417/6/2026
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
AplazadaMedia (5.7)0.58%—389 Project 389 DS BaseAI18/6/202417/6/2026
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
AplazadaAlta (7.5)1.3%—389 Project 389 DS BaseAI28/5/202417/6/2026
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
AplazadaMedia (5.7)0.56%—389 Project 389 DS BaseAI28/5/202426/6/2026
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
ModificadaMedia (6.5)1.3%—Redhat Directory ServerRedhat Enterprise LinuxFedoraproject FedoraPort389 389-ds-base+114/10/202217/6/2026
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
ModificadaMedia (6.5)1.5%—Port389 389-ds-base18/4/202217/6/2026
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
ModificadaAlta (7.5)5.9%—Port389 389-ds-baseRedhat Enterprise Linux16/3/202217/6/2026
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a…
ModificadaAlta (7.5)2.0%—Port389 389-ds-baseRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR Power BIG Endian+418/2/202217/6/2026
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.