Skip to main content

Vendor archive

openldap CVEs

Beta · best-effort

61 CVEs tagged to vendor openldap2 Critical, 28 High, 27 Medium, 4 Low, 0 Unrated.

CVE-2022-29155

Published May 4, 2022

In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query.…

CVSS 9.8 · Critical

CVE-2021-27212

Published Feb 14, 2021

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a deni…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8182

Published Jan 2, 2020

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9287

Published May 29, 2017

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search…

CVSS 6.5 · Medium
Showing 1-25 of 61 CVEsPage 1 of 3