Skip to content
Noroxi

openldap records

61 published records for vendor openldap.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
82%
Median publish → KEV
No record has entered KEV

All records

61 records
  • In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, vi

    CriticalCVSS 9.8No exploitEPSS 64%

    openldap · openldapMay 4, 2022

  • An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r

    HighCVSS 7.5No exploitEPSS 85%

    openldap · openldapJan 26, 2021

  • An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result

    HighCVSS 7.5No exploitEPSS 85%

    openldap · openldapJan 26, 2021

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial

    HighCVSS 7.5No exploitEPSS 77%

    openldap · openldapJan 26, 2021

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de

    HighCVSS 7.5No exploitEPSS 77%

    openldap · openldapJan 26, 2021

  • OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w

    HighCVSS 7.5No exploitEPSS 76%

    openldap · openldapNov 7, 2006

  • In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi

    HighCVSS 7.5No exploitEPSS 64%

    openldap · openldapFeb 13, 2021

  • The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which

    CriticalCVSS 9.8Proof of conceptEPSS 28%

    openldap · openldapJul 28, 2010

  • A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen

    HighCVSS 7.5No exploitEPSS 12%

    openldap · openldapJan 26, 2021

  • contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fr

    HighCVSS 7.5No exploitEPSS 7%

    openldap · openldapDec 18, 2017

  • CVE-2002-1378
    32Monitor

    Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r

    HighCVSS 7.5No exploitEPSS 7%

    openldap · openldapJan 2, 2003

  • CVE-2015-3276
    32Monitor

    The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher stri

    HighCVSS 7.5No exploitEPSS 5%

    openldap · openldapDec 7, 2015

  • An issue was discovered in OpenLDAP 2.x before 2.4.48.

    HighCVSS 7.5No exploitEPSS 5%

    openldap · openldapJul 26, 2019

  • In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon

    HighCVSS 7.5No exploitEPSS 4%

    openldap · openldapApr 28, 2020

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting

    HighCVSS 7.5No exploitEPSS 4%

    openldap · openldapJan 26, 2021

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial

    HighCVSS 7.5No exploitEPSS 4%

    openldap · openldapJan 26, 2021

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial o

    HighCVSS 7.5No exploitEPSS 4%

    openldap · openldapJan 26, 2021

  • A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultin

    HighCVSS 7.5No exploitEPSS 4%

    openldap · openldapJan 26, 2021

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, res

    HighCVSS 7.5No exploitEPSS 4%

    openldap · openldapJan 26, 2021

  • CVE-2014-8182
    31Monitor

    An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.

    HighCVSS 7.5No exploitEPSS 3%

    openldap · openldapJan 2, 2020

  • CVE-2002-1379
    31Monitor

    OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file with

    HighCVSS 7.5No exploitEPSS 3%

    openldap · openldapJan 2, 2003

  • A flaw was found in OpenLDAP.

    HighCVSS 7.5No exploitEPSS 3%

    openldap · openldapMay 18, 2021

  • CVE-2004-0823
    31Monitor

    OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatio

    HighCVSS 7.5No exploitEPSS 3%

    openldap · openldapSep 7, 2004

  • A flaw was found in OpenLDAP in versions before 2.4.56.

    HighCVSS 7.5No exploitEPSS 3%

    openldap · openldapMay 28, 2021

  • CVE-2002-0045
    31Monitor

    slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls

    HighCVSS 7.5No exploitEPSS 2%

    openldap · openldapJan 31, 2002