openldap kayıtları
openldap üreticisine ait 61 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %82
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-399 Resource Management Errors6
- CWE-617 Reachable Assertion6
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-415 Double Free2
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
61 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2022-29155İstismar yok | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, viopenldap · openldap · CWE-89 | Kritik9,8 | — | %64,5 | 4 May 2022 |
55Planlayın | CVE-2020-36228İstismar yok | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, ropenldap · openldap · CWE-191 | Yüksek7,5 | — | %85,0 | 26 Oca 2021 |
55Planlayın | CVE-2020-36221İstismar yok | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resultopenldap · openldap · CWE-191 | Yüksek7,5 | — | %85,0 | 26 Oca 2021 |
53Planlayın | CVE-2020-36222İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial openldap · openldap · CWE-617 | Yüksek7,5 | — | %77,2 | 26 Oca 2021 |
53Planlayın | CVE-2020-36227İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deopenldap · openldap · CWE-835 | Yüksek7,5 | — | %77,2 | 26 Oca 2021 |
53Planlayın | CVE-2006-5779İstismar yok | OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, wopenldap · openldap · CWE-617 | Yüksek7,5 | — | %76,3 | 7 Kas 2006 |
49Planlayın | CVE-2021-27212İstismar yok | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viopenldap · openldap · CWE-617 | Yüksek7,5 | — | %64,1 | 13 Şub 2021 |
48Planlayın | CVE-2010-0211Kavram kanıtı | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which openldap · openldap · CWE-252 | Kritik9,8 | — | %28,5 | 28 Tem 2010 |
34İzleyin | CVE-2020-36230İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemenopenldap · openldap · CWE-617 | Yüksek7,5 | — | %12,3 | 26 Oca 2021 |
32İzleyin | CVE-2017-17740İstismar yok | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fropenldap · openldap · CWE-119 | Yüksek7,5 | — | %7,0 | 18 Ara 2017 |
32İzleyin | CVE-2002-1378İstismar yok | Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -ropenldap · openldap | Yüksek7,5 | — | %7,0 | 2 Oca 2003 |
32İzleyin | CVE-2015-3276İstismar yok | The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher striopenldap · openldap | Yüksek7,5 | — | %5,3 | 7 Ara 2015 |
32İzleyin | CVE-2019-13565İstismar yok | An issue was discovered in OpenLDAP 2.x before 2.4.48.openldap · openldap | Yüksek7,5 | — | %5,0 | 26 Tem 2019 |
31İzleyin | CVE-2020-12243İstismar yok | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon openldap · openldap · CWE-674 | Yüksek7,5 | — | %4,4 | 28 Nis 2020 |
31İzleyin | CVE-2020-36224İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting openldap · openldap · CWE-763 | Yüksek7,5 | — | %4,3 | 26 Oca 2021 |
31İzleyin | CVE-2020-36225İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial openldap · openldap · CWE-415 | Yüksek7,5 | — | %4,3 | 26 Oca 2021 |
31İzleyin | CVE-2020-36223İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial oopenldap · openldap · CWE-125 | Yüksek7,5 | — | %4,3 | 26 Oca 2021 |
31İzleyin | CVE-2020-36229İstismar yok | A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultinopenldap · openldap · CWE-843 | Yüksek7,5 | — | %4,3 | 26 Oca 2021 |
31İzleyin | CVE-2020-36226İstismar yok | A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resopenldap · openldap | Yüksek7,5 | — | %4,2 | 26 Oca 2021 |
31İzleyin | CVE-2014-8182İstismar yok | An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.openldap · openldap · CWE-193 | Yüksek7,5 | — | %3,1 | 2 Oca 2020 |
31İzleyin | CVE-2002-1379İstismar yok | OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file withopenldap · openldap | Yüksek7,5 | — | %2,9 | 2 Oca 2003 |
31İzleyin | CVE-2020-25709İstismar yok | A flaw was found in OpenLDAP.openldap · openldap · CWE-617 | Yüksek7,5 | — | %2,9 | 18 May 2021 |
31İzleyin | CVE-2004-0823İstismar yok | OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatioopenldap · openldap | Yüksek7,5 | — | %2,7 | 7 Eyl 2004 |
31İzleyin | CVE-2020-25710İstismar yok | A flaw was found in OpenLDAP in versions before 2.4.56.openldap · openldap · CWE-617 | Yüksek7,5 | — | %2,7 | 28 May 2021 |
31İzleyin | CVE-2002-0045İstismar yok | slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls openldap · openldap | Yüksek7,5 | — | %2,2 | 31 Oca 2002 |
- CVE-2022-2915558Planlayın
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, vi
KritikCVSS 9,8İstismar yokEPSS %64openldap · openldap4 May 2022
- CVE-2020-3622855Planlayın
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r
YüksekCVSS 7,5İstismar yokEPSS %85openldap · openldap26 Oca 2021
- CVE-2020-3622155Planlayın
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result
YüksekCVSS 7,5İstismar yokEPSS %85openldap · openldap26 Oca 2021
- CVE-2020-3622253Planlayın
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial
YüksekCVSS 7,5İstismar yokEPSS %77openldap · openldap26 Oca 2021
- CVE-2020-3622753Planlayın
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de
YüksekCVSS 7,5İstismar yokEPSS %77openldap · openldap26 Oca 2021
- CVE-2006-577953Planlayın
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w
YüksekCVSS 7,5İstismar yokEPSS %76openldap · openldap7 Kas 2006
- CVE-2021-2721249Planlayın
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi
YüksekCVSS 7,5İstismar yokEPSS %64openldap · openldap13 Şub 2021
- CVE-2010-021148Planlayın
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which
KritikCVSS 9,8Kavram kanıtıEPSS %28openldap · openldap28 Tem 2010
- CVE-2020-3623034İzleyin
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen
YüksekCVSS 7,5İstismar yokEPSS %12openldap · openldap26 Oca 2021
- CVE-2017-1774032İzleyin
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fr
YüksekCVSS 7,5İstismar yokEPSS %7openldap · openldap18 Ara 2017
- CVE-2002-137832İzleyin
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r
YüksekCVSS 7,5İstismar yokEPSS %7openldap · openldap2 Oca 2003
- CVE-2015-327632İzleyin
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher stri
YüksekCVSS 7,5İstismar yokEPSS %5openldap · openldap7 Ara 2015
- CVE-2019-1356532İzleyin
An issue was discovered in OpenLDAP 2.x before 2.4.48.
YüksekCVSS 7,5İstismar yokEPSS %5openldap · openldap26 Tem 2019
- CVE-2020-1224331İzleyin
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon
YüksekCVSS 7,5İstismar yokEPSS %4openldap · openldap28 Nis 2020
- CVE-2020-3622431İzleyin
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting
YüksekCVSS 7,5İstismar yokEPSS %4openldap · openldap26 Oca 2021
- CVE-2020-3622531İzleyin
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial
YüksekCVSS 7,5İstismar yokEPSS %4openldap · openldap26 Oca 2021
- CVE-2020-3622331İzleyin
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial o
YüksekCVSS 7,5İstismar yokEPSS %4openldap · openldap26 Oca 2021
- CVE-2020-3622931İzleyin
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultin
YüksekCVSS 7,5İstismar yokEPSS %4openldap · openldap26 Oca 2021
- CVE-2020-3622631İzleyin
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, res
YüksekCVSS 7,5İstismar yokEPSS %4openldap · openldap26 Oca 2021
- CVE-2014-818231İzleyin
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.
YüksekCVSS 7,5İstismar yokEPSS %3openldap · openldap2 Oca 2020
- CVE-2002-137931İzleyin
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file with
YüksekCVSS 7,5İstismar yokEPSS %3openldap · openldap2 Oca 2003
- CVE-2020-2570931İzleyin
A flaw was found in OpenLDAP.
YüksekCVSS 7,5İstismar yokEPSS %3openldap · openldap18 May 2021
- CVE-2004-082331İzleyin
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatio
YüksekCVSS 7,5İstismar yokEPSS %3openldap · openldap7 Eyl 2004
- CVE-2020-2571031İzleyin
A flaw was found in OpenLDAP in versions before 2.4.56.
YüksekCVSS 7,5İstismar yokEPSS %3openldap · openldap28 May 2021
- CVE-2002-004531İzleyin
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls
YüksekCVSS 7,5İstismar yokEPSS %2openldap · openldap31 Oca 2002