CVE-2026-86344
- EPSS 0.35%
- Veröffentlicht 01.10.2026 21:29:55
- Zuletzt bearbeitet 02.10.2026 19:16:42
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thre...
CVE-2026-76560
- EPSS 0.37%
- Veröffentlicht 07.09.2026 13:18:09
- Zuletzt bearbeitet 08.09.2026 22:19:15
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks int...
CVE-2026-18663
- EPSS 0.4%
- Veröffentlicht 12.08.2026 09:35:26
- Zuletzt bearbeitet 14.08.2026 19:07:46
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the...
CVE-2024-5953
- EPSS 0.58%
- Veröffentlicht 18.06.2024 10:15:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
CVE-2010-3282
- EPSS 0.26%
- Veröffentlicht 09.01.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:26
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-root...