By weakness (CWE)

CWE-125: related vulnerabilities

CVEs classified under CWE-125. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

201 published vulnerabilities · page 3 of 3

  • CVE-2026-11786LOW 1.9

    A parsing flaw in 389 Directory Server can cause the LDIF (LDAP Data Interchange Format) parser to read past the boundary of allocated memory when it encounters attribute types ending with semicolons during database imports. The defect is detectable only under memory instrumentation tools (such as AddressSanitizer) and does not cause immediate functional failure or crashes under normal operation. This is a low-severity out-of-bounds read affecting local, high-privileged operations.