openldap records
61 published records for vendor openldap.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 82%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-399 Resource Management Errors6
- CWE-617 Reachable Assertion6
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-415 Double Free2
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
The weakness classes this vendor ships most often: where to look.
CWEAll records
61 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2022-29155No exploit | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, viopenldap · openldap · CWE-89 | Critical9.8 | — | 64.5% | May 4, 2022 |
55Plan | CVE-2020-36228No exploit | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, ropenldap · openldap · CWE-191 | High7.5 | — | 85.0% | Jan 26, 2021 |
55Plan | CVE-2020-36221No exploit | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resultopenldap · openldap · CWE-191 | High7.5 | — | 85.0% | Jan 26, 2021 |
53Plan | CVE-2020-36222No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial openldap · openldap · CWE-617 | High7.5 | — | 77.2% | Jan 26, 2021 |
53Plan | CVE-2020-36227No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deopenldap · openldap · CWE-835 | High7.5 | — | 77.2% | Jan 26, 2021 |
53Plan | CVE-2006-5779No exploit | OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, wopenldap · openldap · CWE-617 | High7.5 | — | 76.3% | Nov 7, 2006 |
49Plan | CVE-2021-27212No exploit | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viopenldap · openldap · CWE-617 | High7.5 | — | 64.1% | Feb 13, 2021 |
48Plan | CVE-2010-0211Proof of concept | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which openldap · openldap · CWE-252 | Critical9.8 | — | 28.5% | Jul 28, 2010 |
34Monitor | CVE-2020-36230No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemenopenldap · openldap · CWE-617 | High7.5 | — | 12.3% | Jan 26, 2021 |
32Monitor | CVE-2017-17740No exploit | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fropenldap · openldap · CWE-119 | High7.5 | — | 7.0% | Dec 18, 2017 |
32Monitor | CVE-2002-1378No exploit | Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -ropenldap · openldap | High7.5 | — | 7.0% | Jan 2, 2003 |
32Monitor | CVE-2015-3276No exploit | The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher striopenldap · openldap | High7.5 | — | 5.3% | Dec 7, 2015 |
32Monitor | CVE-2019-13565No exploit | An issue was discovered in OpenLDAP 2.x before 2.4.48.openldap · openldap | High7.5 | — | 5.0% | Jul 26, 2019 |
31Monitor | CVE-2020-12243No exploit | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon openldap · openldap · CWE-674 | High7.5 | — | 4.4% | Apr 28, 2020 |
31Monitor | CVE-2020-36224No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting openldap · openldap · CWE-763 | High7.5 | — | 4.3% | Jan 26, 2021 |
31Monitor | CVE-2020-36225No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial openldap · openldap · CWE-415 | High7.5 | — | 4.3% | Jan 26, 2021 |
31Monitor | CVE-2020-36223No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial oopenldap · openldap · CWE-125 | High7.5 | — | 4.3% | Jan 26, 2021 |
31Monitor | CVE-2020-36229No exploit | A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultinopenldap · openldap · CWE-843 | High7.5 | — | 4.3% | Jan 26, 2021 |
31Monitor | CVE-2020-36226No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resopenldap · openldap | High7.5 | — | 4.2% | Jan 26, 2021 |
31Monitor | CVE-2014-8182No exploit | An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.openldap · openldap · CWE-193 | High7.5 | — | 3.1% | Jan 2, 2020 |
31Monitor | CVE-2002-1379No exploit | OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file withopenldap · openldap | High7.5 | — | 2.9% | Jan 2, 2003 |
31Monitor | CVE-2020-25709No exploit | A flaw was found in OpenLDAP.openldap · openldap · CWE-617 | High7.5 | — | 2.9% | May 18, 2021 |
31Monitor | CVE-2004-0823No exploit | OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatioopenldap · openldap | High7.5 | — | 2.7% | Sep 7, 2004 |
31Monitor | CVE-2020-25710No exploit | A flaw was found in OpenLDAP in versions before 2.4.56.openldap · openldap · CWE-617 | High7.5 | — | 2.7% | May 28, 2021 |
31Monitor | CVE-2002-0045No exploit | slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls openldap · openldap | High7.5 | — | 2.2% | Jan 31, 2002 |
- CVE-2022-2915558Plan
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, vi
CriticalCVSS 9.8No exploitEPSS 64%openldap · openldapMay 4, 2022
- CVE-2020-3622855Plan
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r
HighCVSS 7.5No exploitEPSS 85%openldap · openldapJan 26, 2021
- CVE-2020-3622155Plan
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result
HighCVSS 7.5No exploitEPSS 85%openldap · openldapJan 26, 2021
- CVE-2020-3622253Plan
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial
HighCVSS 7.5No exploitEPSS 77%openldap · openldapJan 26, 2021
- CVE-2020-3622753Plan
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de
HighCVSS 7.5No exploitEPSS 77%openldap · openldapJan 26, 2021
- CVE-2006-577953Plan
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w
HighCVSS 7.5No exploitEPSS 76%openldap · openldapNov 7, 2006
- CVE-2021-2721249Plan
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi
HighCVSS 7.5No exploitEPSS 64%openldap · openldapFeb 13, 2021
- CVE-2010-021148Plan
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which
CriticalCVSS 9.8Proof of conceptEPSS 28%openldap · openldapJul 28, 2010
- CVE-2020-3623034Monitor
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen
HighCVSS 7.5No exploitEPSS 12%openldap · openldapJan 26, 2021
- CVE-2017-1774032Monitor
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fr
HighCVSS 7.5No exploitEPSS 7%openldap · openldapDec 18, 2017
- CVE-2002-137832Monitor
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r
HighCVSS 7.5No exploitEPSS 7%openldap · openldapJan 2, 2003
- CVE-2015-327632Monitor
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher stri
HighCVSS 7.5No exploitEPSS 5%openldap · openldapDec 7, 2015
- CVE-2019-1356532Monitor
An issue was discovered in OpenLDAP 2.x before 2.4.48.
HighCVSS 7.5No exploitEPSS 5%openldap · openldapJul 26, 2019
- CVE-2020-1224331Monitor
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon
HighCVSS 7.5No exploitEPSS 4%openldap · openldapApr 28, 2020
- CVE-2020-3622431Monitor
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting
HighCVSS 7.5No exploitEPSS 4%openldap · openldapJan 26, 2021
- CVE-2020-3622531Monitor
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial
HighCVSS 7.5No exploitEPSS 4%openldap · openldapJan 26, 2021
- CVE-2020-3622331Monitor
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial o
HighCVSS 7.5No exploitEPSS 4%openldap · openldapJan 26, 2021
- CVE-2020-3622931Monitor
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultin
HighCVSS 7.5No exploitEPSS 4%openldap · openldapJan 26, 2021
- CVE-2020-3622631Monitor
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, res
HighCVSS 7.5No exploitEPSS 4%openldap · openldapJan 26, 2021
- CVE-2014-818231Monitor
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.
HighCVSS 7.5No exploitEPSS 3%openldap · openldapJan 2, 2020
- CVE-2002-137931Monitor
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file with
HighCVSS 7.5No exploitEPSS 3%openldap · openldapJan 2, 2003
- CVE-2020-2570931Monitor
A flaw was found in OpenLDAP.
HighCVSS 7.5No exploitEPSS 3%openldap · openldapMay 18, 2021
- CVE-2004-082331Monitor
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatio
HighCVSS 7.5No exploitEPSS 3%openldap · openldapSep 7, 2004
- CVE-2020-2571031Monitor
A flaw was found in OpenLDAP in versions before 2.4.56.
HighCVSS 7.5No exploitEPSS 3%openldap · openldapMay 28, 2021
- CVE-2002-004531Monitor
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls
HighCVSS 7.5No exploitEPSS 2%openldap · openldapJan 31, 2002