Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.1% | — | Debian Nss-ldapDebian Linux | 31/3/2009 | 16/6/2026 | nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field. | |
| Modificada | Media (4.3) | 1.2% | — | NSS Ldap | 13/11/2007 | 16/6/2026 | Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being… | |
| Modificada | Media (5) | 2.8% | — | Padl NSS LdapPadl PAM Ldap | 30/6/2005 | 16/6/2026 | pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password. | |
| Modificada | Alta (7.5) | 2.9% | — | C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap | 12/8/2002 | 16/6/2026 | Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. | |
| Modificada | Alta (7.5) | 2.5% | — | Padl Software NSS Ldap | 12/8/2002 | 16/6/2026 | Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Baja (1.2) | 0.60% | — | Padl Software NSS Ldap | 11/12/2000 | 16/6/2026 | nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests. |