Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.56%—389 Directory ServerAI7/9/20268/9/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An…
Pendiente de análisisAlta (7.5)0.85%—389 Project 389 Directory ServerAI7/9/20269/9/2026
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
Pendiente de análisisAlta (7.5)0.84%—389 Project 389 Directory ServerAI7/9/20268/9/2026
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed…
Pendiente de análisisAlta (7.5)0.56%—389 Project 389 Directory ServerAI7/9/20268/9/2026
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an…
AplazadaMedia (5.4)0.24%—Cube-root Directory-serveAI10/8/20263/9/2026
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.
AplazadaCrítica (9.1)0.74%—Cube Root Directory ServeAI10/8/202628/8/2026
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
Pendiente de análisisMedia (6.5)0.43%—389 Project 389 Directory ServerAI10/8/202614/8/2026
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to…
AnalizadaMedia (5.4)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux3/8/20269/8/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on…
ModificadaAlta (7.5)0.83%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/202618/8/2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by…
ModificadaAlta (7.5)0.53%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/202618/8/2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the…
AnalizadaBaja (3.7)0.36%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux8/7/20269/7/2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though…
AnalizadaMedia (4.4)0.11%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux7/7/20269/7/2026
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
AnalizadaMedia (5.3)0.49%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux7/7/20269/7/2026
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An…
Pendiente de análisisAlta (8.8)0.49%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI7/7/20268/7/2026
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds…
ModificadaMedia (5)0.35%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux18/6/202630/6/2026
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP…
AnalizadaMedia (5.4)0.23%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux17/6/202628/6/2026
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace…
Pendiente de análisisAlta (7.6)0.68%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI11/6/202615/7/2026
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of…
Pendiente de análisisMedia (6.5)0.35%—389 Project 389 Directory ServerAI10/6/202630/6/2026
A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager…
ModificadaMedia (4.9)0.28%—Redhat 389 Directory Server9/6/20267/8/2026
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server…
Pendiente de análisisBaja (3.3)0.26%—389 Project Directory ServerAI9/6/202623/7/2026
A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default…
ModificadaMedia (4.9)0.29%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of…
ModificadaMedia (6.5)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
ModificadaAlta (7.5)0.56%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202618/8/2026
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
ModificadaMedia (6.3)0.18%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
ModificadaMedia (6.5)0.16%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.