Записи openldap
61 опубликованных записей вендора openldap.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 82 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-399 Resource Management Errors6
- CWE-617 Reachable Assertion6
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-415 Double Free2
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
61 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2022-29155Эксплойта нет | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, viopenldap · openldap · CWE-89 | Критическая9,8 | — | 64,5 % | 4 мая 2022 г. |
55В плане | CVE-2020-36228Эксплойта нет | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, ropenldap · openldap · CWE-191 | Высокая7,5 | — | 85,0 % | 26 янв. 2021 г. |
55В плане | CVE-2020-36221Эксплойта нет | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resultopenldap · openldap · CWE-191 | Высокая7,5 | — | 85,0 % | 26 янв. 2021 г. |
53В плане | CVE-2020-36222Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial openldap · openldap · CWE-617 | Высокая7,5 | — | 77,2 % | 26 янв. 2021 г. |
53В плане | CVE-2020-36227Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deopenldap · openldap · CWE-835 | Высокая7,5 | — | 77,2 % | 26 янв. 2021 г. |
53В плане | CVE-2006-5779Эксплойта нет | OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, wopenldap · openldap · CWE-617 | Высокая7,5 | — | 76,3 % | 7 нояб. 2006 г. |
49В плане | CVE-2021-27212Эксплойта нет | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viopenldap · openldap · CWE-617 | Высокая7,5 | — | 64,1 % | 13 февр. 2021 г. |
48В плане | CVE-2010-0211Proof of concept | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which openldap · openldap · CWE-252 | Критическая9,8 | — | 28,5 % | 28 июл. 2010 г. |
34Наблюдать | CVE-2020-36230Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemenopenldap · openldap · CWE-617 | Высокая7,5 | — | 12,3 % | 26 янв. 2021 г. |
32Наблюдать | CVE-2017-17740Эксплойта нет | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fropenldap · openldap · CWE-119 | Высокая7,5 | — | 7,0 % | 18 дек. 2017 г. |
32Наблюдать | CVE-2002-1378Эксплойта нет | Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -ropenldap · openldap | Высокая7,5 | — | 7,0 % | 2 янв. 2003 г. |
32Наблюдать | CVE-2015-3276Эксплойта нет | The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher striopenldap · openldap | Высокая7,5 | — | 5,3 % | 7 дек. 2015 г. |
32Наблюдать | CVE-2019-13565Эксплойта нет | An issue was discovered in OpenLDAP 2.x before 2.4.48.openldap · openldap | Высокая7,5 | — | 5,0 % | 26 июл. 2019 г. |
31Наблюдать | CVE-2020-12243Эксплойта нет | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon openldap · openldap · CWE-674 | Высокая7,5 | — | 4,4 % | 28 апр. 2020 г. |
31Наблюдать | CVE-2020-36224Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting openldap · openldap · CWE-763 | Высокая7,5 | — | 4,3 % | 26 янв. 2021 г. |
31Наблюдать | CVE-2020-36225Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial openldap · openldap · CWE-415 | Высокая7,5 | — | 4,3 % | 26 янв. 2021 г. |
31Наблюдать | CVE-2020-36223Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial oopenldap · openldap · CWE-125 | Высокая7,5 | — | 4,3 % | 26 янв. 2021 г. |
31Наблюдать | CVE-2020-36229Эксплойта нет | A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultinopenldap · openldap · CWE-843 | Высокая7,5 | — | 4,3 % | 26 янв. 2021 г. |
31Наблюдать | CVE-2020-36226Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resopenldap · openldap | Высокая7,5 | — | 4,2 % | 26 янв. 2021 г. |
31Наблюдать | CVE-2014-8182Эксплойта нет | An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.openldap · openldap · CWE-193 | Высокая7,5 | — | 3,1 % | 2 янв. 2020 г. |
31Наблюдать | CVE-2002-1379Эксплойта нет | OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file withopenldap · openldap | Высокая7,5 | — | 2,9 % | 2 янв. 2003 г. |
31Наблюдать | CVE-2020-25709Эксплойта нет | A flaw was found in OpenLDAP.openldap · openldap · CWE-617 | Высокая7,5 | — | 2,9 % | 18 мая 2021 г. |
31Наблюдать | CVE-2004-0823Эксплойта нет | OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatioopenldap · openldap | Высокая7,5 | — | 2,7 % | 7 сент. 2004 г. |
31Наблюдать | CVE-2020-25710Эксплойта нет | A flaw was found in OpenLDAP in versions before 2.4.56.openldap · openldap · CWE-617 | Высокая7,5 | — | 2,7 % | 28 мая 2021 г. |
31Наблюдать | CVE-2002-0045Эксплойта нет | slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls openldap · openldap | Высокая7,5 | — | 2,2 % | 31 янв. 2002 г. |
- CVE-2022-2915558В плане
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, vi
КритическаяCVSS 9,8Эксплойта нетEPSS 64 %openldap · openldap4 мая 2022 г.
- CVE-2020-3622855В плане
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r
ВысокаяCVSS 7,5Эксплойта нетEPSS 85 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622155В плане
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result
ВысокаяCVSS 7,5Эксплойта нетEPSS 85 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622253В плане
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 77 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622753В плане
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in de
ВысокаяCVSS 7,5Эксплойта нетEPSS 77 %openldap · openldap26 янв. 2021 г.
- CVE-2006-577953В плане
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w
ВысокаяCVSS 7,5Эксплойта нетEPSS 76 %openldap · openldap7 нояб. 2006 г.
- CVE-2021-2721249В плане
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 64 %openldap · openldap13 февр. 2021 г.
- CVE-2010-021148В плане
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which
КритическаяCVSS 9,8Proof of conceptEPSS 28 %openldap · openldap28 июл. 2010 г.
- CVE-2020-3623034Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %openldap · openldap26 янв. 2021 г.
- CVE-2017-1774032Наблюдать
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to fr
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %openldap · openldap18 дек. 2017 г.
- CVE-2002-137832Наблюдать
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %openldap · openldap2 янв. 2003 г.
- CVE-2015-327632Наблюдать
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher stri
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %openldap · openldap7 дек. 2015 г.
- CVE-2019-1356532Наблюдать
An issue was discovered in OpenLDAP 2.x before 2.4.48.
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %openldap · openldap26 июл. 2019 г.
- CVE-2020-1224331Наблюдать
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap28 апр. 2020 г.
- CVE-2020-3622431Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622531Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622331Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial o
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622931Наблюдать
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resultin
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622631Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, res
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap26 янв. 2021 г.
- CVE-2014-818231Наблюдать
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openldap · openldap2 янв. 2020 г.
- CVE-2002-137931Наблюдать
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file with
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openldap · openldap2 янв. 2003 г.
- CVE-2020-2570931Наблюдать
A flaw was found in OpenLDAP.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openldap · openldap18 мая 2021 г.
- CVE-2004-082331Наблюдать
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authenticatio
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openldap · openldap7 сент. 2004 г.
- CVE-2020-2571031Наблюдать
A flaw was found in OpenLDAP in versions before 2.4.56.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openldap · openldap28 мая 2021 г.
- CVE-2002-004531Наблюдать
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openldap · openldap31 янв. 2002 г.