CVE-2026-11787
- EPSS 0.18%
- Veröffentlicht 09.06.2026 13:02:53
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
CVE-2026-11788
- EPSS 0.58%
- Veröffentlicht 09.06.2026 13:02:53
- Zuletzt bearbeitet 08.10.2026 15:17:47
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure...
CVE-2026-11785
- EPSS 0.18%
- Veröffentlicht 09.06.2026 12:57:59
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
CVE-2026-11786
- EPSS 0.16%
- Veröffentlicht 09.06.2026 12:57:59
- Zuletzt bearbeitet 23.07.2026 08:10:00
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.
CVE-2026-11611
- EPSS 0.24%
- Veröffentlicht 08.06.2026 16:17:59
- Zuletzt bearbeitet 23.07.2026 07:10:00
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin ...
CVE-2026-50263
- EPSS 0.14%
- Veröffentlicht 05.06.2026 10:36:46
- Zuletzt bearbeitet 05.08.2026 00:17:04
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
CVE-2026-50262
- EPSS 0.13%
- Veröffentlicht 05.06.2026 10:36:43
- Zuletzt bearbeitet 05.08.2026 00:17:04
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosu...
CVE-2026-50264
- EPSS 0.15%
- Veröffentlicht 05.06.2026 10:36:37
- Zuletzt bearbeitet 27.07.2026 13:18:19
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. Thi...
CVE-2026-50261
- EPSS 0.15%
- Veröffentlicht 05.06.2026 10:36:33
- Zuletzt bearbeitet 05.08.2026 13:23:33
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those cou...
CVE-2026-50260
- EPSS 0.15%
- Veröffentlicht 05.06.2026 10:36:30
- Zuletzt bearbeitet 05.08.2026 13:23:32
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. ...