Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

ubuntu логотип

CVE-2026-9064

4 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-9064

4 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-9064

4 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-9064

4 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21011-1

3 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2419-1

3 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2418-1

3 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2417-1

3 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2316-1

3 месяца назад

Security update for 389-ds

EPSS: Низкий
rocky логотип

RLSA-2026:26459

3 месяца назад

Important: 389-ds:1.4 security update

EPSS: Низкий
rocky логотип

RLSA-2026:26456

3 месяца назад

Important: 389-ds-base security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:26455

3 месяца назад

Important: 389-ds-base security, bug fix, and enhancement update

EPSS: Низкий
github логотип

GHSA-7r3c-wfgh-x96c

4 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-26459

3 месяца назад

ELSA-2026-26459: 389-ds:1.4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26456

около 2 месяцев назад

ELSA-2026-26456: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26455

3 месяца назад

ELSA-2026-26455: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26453

2 месяца назад

ELSA-2026-26453: 389-ds-base security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-12878

4 месяца назад

Уязвимость сервера службы каталогов 389 Directory Server, связанная с выделением неограниченной памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21011-1

Security update for 389-ds

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2419-1

Security update for 389-ds

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2418-1

Security update for 389-ds

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2417-1

Security update for 389-ds

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2316-1

Security update for 389-ds

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:26459

Important: 389-ds:1.4 security update

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:26456

Important: 389-ds-base security, bug fix, and enhancement update

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:26455

Important: 389-ds-base security, bug fix, and enhancement update

1%
Низкий
3 месяца назад
github логотип
GHSA-7r3c-wfgh-x96c

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-26459

ELSA-2026-26459: 389-ds:1.4 security update (IMPORTANT)

1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-26456

ELSA-2026-26456: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

1%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-26455

ELSA-2026-26455: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-26453

ELSA-2026-26453: 389-ds-base security update (IMPORTANT)

1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-12878

Уязвимость сервера службы каталогов 389 Directory Server, связанная с выделением неограниченной памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу