Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openldap HIGH 7.5
CVE-2017-17740EPSS 7%

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buff…

Fix: 6.5.1 / 21.1.2+
Fix from $1,950 2017-12-18
Openldap MEDIUM 5.0
CVE-2015-6908EPSS 20%

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable as…

Fix: after 10.11.1
Fix from $1,600 2015-09-11
Openldap MEDIUM 5.0
CVE-2015-1546

Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-02-12
Openldap MEDIUM 5.0
CVE-2015-1545EPSS 11%

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service…

No fix yet
Fix from $1,600 2015-02-12
Openldap MEDIUM 5.0
CVE-2011-1081EPSS 14%

modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Na…

Patch available
Fix from $1,600 2011-03-20
Openldap MEDIUM 6.8
CVE-2011-1025

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attack…

Patch available
Fix from $1,600 2011-03-20
Openldap MEDIUM 5.0
CVE-2010-0212EPSS 6%

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is no…

Patch available
Fix from $1,600 2010-07-28
Openldap MEDIUM 5.0
CVE-2008-2952EPSS 13%

liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams t…

Mitigation only
Fix from $1,600 2008-07-01
Openldap HIGH 7.1
CVE-2007-5707

OpenLDAP before 2.3.39 allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribut…

Patch available
Fix from $1,950 2007-10-30
Openldap HIGH 7.1
CVE-2007-5708

slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant …

Patch available
Fix from $1,950 2007-10-30
Openldap MEDIUM 5.1
CVE-2006-6493EPSS 9%

Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enabl…

Fix: after 2.4.3
Fix from $1,600 2006-12-13
Openldap MEDIUM 5.0
CVE-2006-2754

Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.

Patch available
Fix from $1,600 2006-06-01
Openldap HIGH 7.2
CVE-2005-4442

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a mal…

Fix: after 2.2.28_r2
Fix from $1,950 2005-12-21
Openldap MEDIUM 5.0
CVE-2004-1880

Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).

Patch available
Fix from $1,600 2004-12-31
Openldap HIGH 7.5
CVE-2004-0823

OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes…

Patch available
Fix from $1,950 2004-09-07
Openldap MEDIUM 5.0
CVE-2003-1201

ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_…

Fix: after 2.1.12
Fix from $1,600 2003-03-20
Openldap HIGH 7.5
CVE-2002-1378EPSS 7%

Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r paramete…

Fix: after 2.2.0
Fix from $1,950 2003-01-02
Openldap HIGH 7.5
CVE-2002-1379

OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applic…

Fix: after 2.2.0
Fix from $1,950 2003-01-02