CVE-2026-12528
- EPSS 0.23%
- Veröffentlicht 17.06.2026 14:27:27
- Zuletzt bearbeitet 28.06.2026 00:22:17
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validat...
CVE-2026-11774
- EPSS 0.8%
- Veröffentlicht 11.06.2026 17:54:34
- Zuletzt bearbeitet 15.07.2026 02:18:03
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the ...
CVE-2026-11790
- EPSS 0.29%
- Veröffentlicht 09.06.2026 13:09:29
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause ex...
CVE-2026-11789
- EPSS 0.28%
- Veröffentlicht 09.06.2026 13:02:59
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server duri...
CVE-2026-11788
- EPSS 0.58%
- Veröffentlicht 09.06.2026 13:02:53
- Zuletzt bearbeitet 18.08.2026 15:16:48
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure...
CVE-2026-11787
- EPSS 0.18%
- Veröffentlicht 09.06.2026 13:02:53
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
CVE-2026-11786
- EPSS 0.16%
- Veröffentlicht 09.06.2026 12:57:59
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.
CVE-2026-11785
- EPSS 0.18%
- Veröffentlicht 09.06.2026 12:57:59
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
CVE-2026-11611
- EPSS 0.24%
- Veröffentlicht 08.06.2026 16:17:59
- Zuletzt bearbeitet 23.07.2026 07:10:00
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin ...
CVE-2026-9064
- EPSS 0.82%
- Veröffentlicht 20.05.2026 09:00:42
- Zuletzt bearbeitet 21.08.2026 12:16:37
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request c...