Skip to main content

Vendor archive

openldap CVEs

Beta · best-effort

61 CVEs tagged to vendor openldap2 Critical, 28 High, 27 Medium, 4 Low, 0 Unrated.

CVE-2015-3276

Published Dec 7, 2015

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than in…

CVSS 7.5 · High

CVE-2015-6908

Published Sep 11, 2015

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9713

Published Apr 1, 2015

The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attrib…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1545

Published Feb 12, 2015

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4449

Published Feb 5, 2014

The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1164

Published Jun 29, 2012

slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2668

Published Jun 17, 2012

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4079

Published Oct 27, 2011

Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string tha…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1081

Published Mar 20, 2011

modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1025

Published Mar 20, 2011

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1024

Published Mar 20, 2011

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0212

Published Jul 28, 2010

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2952

Published Jul 1, 2008

liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0658

Published Feb 13, 2008

slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6698

Published Feb 1, 2008

The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the N…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5707

Published Oct 30, 2007

OpenLDAP before 2.3.39 allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute. NOTE: this has been report…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5708

Published Oct 30, 2007

slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which preve…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6493

Published Dec 13, 2006

Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) optio…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4600

Published Sep 7, 2006

slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2754

Published Jun 1, 2006

Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4442

Published Dec 21, 2005

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Po…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 61 CVEsPage 2 of 3