Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.42%—Openvpn Auth LdapAI27/6/202417/6/2026
Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a…
ModificadaCrítica (9.8)0.85%—Ttrrs-auth-ldap Project Ttrrs-auth-ldap7/1/202317/6/2026
A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to version 2.0b1 is able to address this issue. The patch is identified as…
ModificadaCrítica (9.8)1.6%—Prosody MOD Auth LdapProsody MOD Auth Ldap2Debian Linux28/1/202017/6/2026
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.
ModificadaAlta (7.5)5.4%—Dave Carrigan Auth Ldap9/1/200616/6/2026
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
ModificadaAlta (7.5)2.9%—C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap12/8/200216/6/2026
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.