CVE-2025-3416
- EPSS 0.07%
- Veröffentlicht 08.04.2025 18:24:22
- Zuletzt bearbeitet 09.04.2025 20:02:41
A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the in...
CVE-2025-2487
- EPSS 0.49%
- Veröffentlicht 18.03.2025 16:25:43
- Zuletzt bearbeitet 13.05.2025 14:15:20
A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a lda...
CVE-2024-6237
- EPSS 0.55%
- Veröffentlicht 09.07.2024 17:15:48
- Zuletzt bearbeitet 21.11.2024 09:49:15
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
CVE-2024-1062
- EPSS 0.02%
- Veröffentlicht 12.02.2024 13:15:09
- Zuletzt bearbeitet 18.02.2025 11:15:11
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
CVE-2023-1055
- EPSS 0.05%
- Veröffentlicht 27.02.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:38:22
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the co...
CVE-2022-2850
- EPSS 0.27%
- Veröffentlicht 14.10.2022 18:15:14
- Zuletzt bearbeitet 15.05.2025 15:15:53
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. ...
CVE-2022-1949
- EPSS 0.51%
- Veröffentlicht 02.06.2022 14:15:34
- Zuletzt bearbeitet 13.12.2024 18:47:19
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unau...
CVE-2020-35518
- EPSS 0.8%
- Veröffentlicht 26.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:28
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
CVE-2010-3282
- EPSS 0.16%
- Veröffentlicht 09.01.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:26
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-root...
CVE-2010-2222
- EPSS 0.44%
- Veröffentlicht 05.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:16:11
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.