|
1
|
4.9
-
|
MEDIUM
Network
|
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-11790
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-13 03:21
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
6.5
-
|
MEDIUM
Network
|
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a…
Update
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-11789
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-13 03:30
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
7.5
-
|
HIGH
Network
|
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the L…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-11788
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-13 03:30
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
6.3
-
|
MEDIUM
Network
|
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that …
Update
|
CWE-126
Buffer Over-read
|
CVE-2026-11787
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-13 03:38
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
6.5
-
|
MEDIUM
Network
|
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11786
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-13 03:40
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
4.3
-
|
MEDIUM
Network
|
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated user…
Update
|
CWE-843
Type Confusion
|
CVE-2026-11785
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:10.0:*
|
|
|
|
|
2026-06-13 03:47
2026-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
5.5
-
|
MEDIUM
Local
|
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, le…
|
CWE-416
Use After Free
|
CVE-2026-50263
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-12 04:46
2026-06-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroy…
|
CWE-416
Use After Free
|
CVE-2026-50260
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-12 03:36
2026-06-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
7.8
-
|
HIGH
Local
|
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function Ch…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-50259
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-9 03:28
2026-06-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
7.8
-
|
HIGH
Local
|
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify o…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-50258
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-06-9 01:46
2026-06-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|