Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

github логотип

GHSA-7r3c-wfgh-x96c

2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-9064

2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-9064

2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-9064

2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-9064

2 месяца назад

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21011-1

около 1 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2419-1

около 1 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2418-1

около 1 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2417-1

около 1 месяца назад

Security update for 389-ds

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2316-1

около 2 месяцев назад

Security update for 389-ds

EPSS: Низкий
rocky логотип

RLSA-2026:26459

около 1 месяца назад

Important: 389-ds:1.4 security update

EPSS: Низкий
rocky логотип

RLSA-2026:26456

около 1 месяца назад

Important: 389-ds-base security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:26455

около 1 месяца назад

Important: 389-ds-base security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26459

около 1 месяца назад

ELSA-2026-26459: 389-ds:1.4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26456

10 дней назад

ELSA-2026-26456: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26455

около 1 месяца назад

ELSA-2026-26455: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26453

17 дней назад

ELSA-2026-26453: 389-ds-base security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7r3c-wfgh-x96c

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...

CVSS3: 7.5
1%
Низкий
2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21011-1

Security update for 389-ds

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2419-1

Security update for 389-ds

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2418-1

Security update for 389-ds

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2417-1

Security update for 389-ds

1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2316-1

Security update for 389-ds

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:26459

Important: 389-ds:1.4 security update

1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:26456

Important: 389-ds-base security, bug fix, and enhancement update

1%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:26455

Important: 389-ds-base security, bug fix, and enhancement update

1%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-26459

ELSA-2026-26459: 389-ds:1.4 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-26456

ELSA-2026-26456: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

10 дней назад
oracle-oval логотип
ELSA-2026-26455

ELSA-2026-26455: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-26453

ELSA-2026-26453: 389-ds-base security update (IMPORTANT)

17 дней назад

Уязвимостей на страницу