Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.56% | — | 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An… | |
| Pendiente de análisis | Alta (7.5) | 0.85% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 9/9/2026 | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.84% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed… | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an… | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | |
| Pendiente de análisis | Media (6.5) | 0.43% | — | 389 Project 389 Directory ServerAI | 10/8/2026 | 14/8/2026 | A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to… | |
| Analizada | Media (5.4) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 3/8/2026 | 9/8/2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on… | |
| Modificada | Alta (7.5) | 0.83% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 18/8/2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by… | |
| Modificada | Alta (7.5) | 0.53% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 18/8/2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the… | |
| Analizada | Baja (3.7) | 0.36% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 8/7/2026 | 9/7/2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though… | |
| Analizada | Media (4.4) | 0.11% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 7/7/2026 | 9/7/2026 | A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks. | |
| Analizada | Media (5.3) | 0.49% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 7/7/2026 | 9/7/2026 | A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 7/7/2026 | 8/7/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds… | |
| Modificada | Media (5) | 0.35% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 18/6/2026 | 30/6/2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP… | |
| Analizada | Media (5.4) | 0.23% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 17/6/2026 | 28/6/2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace… | |
| Pendiente de análisis | Alta (7.6) | 0.68% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 11/6/2026 | 15/7/2026 | An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | 389 Project 389 Directory ServerAI | 10/6/2026 | 30/6/2026 | A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager… | |
| Modificada | Media (4.9) | 0.28% | — | Redhat 389 Directory Server | 9/6/2026 | 7/8/2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server… | |
| Pendiente de análisis | Baja (3.3) | 0.26% | — | 389 Project Directory ServerAI | 9/6/2026 | 23/7/2026 | A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default… | |
| Modificada | Media (4.9) | 0.29% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of… | |
| Modificada | Media (6.5) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication. | |
| Modificada | Alta (7.5) | 0.56% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 18/8/2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure. | |
| Modificada | Media (6.3) | 0.18% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. | |
| Modificada | Media (6.5) | 0.16% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation. |