Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 21

Количество 21

oracle-oval логотип

ELSA-2026-55530

2 дня назад

ELSA-2026-55530: 389-ds:1.4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55424

2 дня назад

ELSA-2026-55424: 389-ds-base security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55423

2 дня назад

ELSA-2026-55423: 389-ds-base security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-11770

19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-11770

19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-11770

19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-11770

19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote at ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r7mx-568f-jgg3

19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-15722

19 дней назад

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-15722

19 дней назад

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-15722

19 дней назад

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-15722

19 дней назад

A stack buffer overflow flaw was found in 389 Directory Server (389-ds ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-11788

2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-11788

4 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-11788

2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-11788

2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plug ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-5gg4-m865-6qwr

19 дней назад

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x2wj-4r98-4867

2 месяца назад

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3138-1

30 дней назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3137-1

30 дней назад

Security update for 389-ds

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-55530

ELSA-2026-55530: 389-ds:1.4 security update (IMPORTANT)

2 дня назад
oracle-oval логотип
ELSA-2026-55424

ELSA-2026-55424: 389-ds-base security update (IMPORTANT)

2 дня назад
oracle-oval логотип
ELSA-2026-55423

ELSA-2026-55423: 389-ds-base security update (IMPORTANT)

2 дня назад
ubuntu логотип
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
1%
Низкий
19 дней назад
redhat логотип
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
1%
Низкий
19 дней назад
nvd логотип
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
1%
Низкий
19 дней назад
debian логотип
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote at ...

CVSS3: 7.5
1%
Низкий
19 дней назад
github логотип
GHSA-r7mx-568f-jgg3

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
1%
Низкий
19 дней назад
ubuntu логотип
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
1%
Низкий
19 дней назад
redhat логотип
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
1%
Низкий
19 дней назад
nvd логотип
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
1%
Низкий
19 дней назад
debian логотип
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds ...

CVSS3: 7.5
1%
Низкий
19 дней назад
ubuntu логотип
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plug ...

CVSS3: 5.9
1%
Низкий
2 месяца назад
github логотип
GHSA-5gg4-m865-6qwr

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

CVSS3: 7.5
1%
Низкий
19 дней назад
github логотип
GHSA-x2wj-4r98-4867

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

CVSS3: 5.9
1%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3138-1

Security update for 389-ds

30 дней назад
suse-cvrf логотип
SUSE-SU-2026:3137-1

Security update for 389-ds

30 дней назад

Уязвимостей на страницу