CVE-2023-2953
- EPSS 1.11%
- Veröffentlicht 30.05.2023 22:15:10
- Zuletzt bearbeitet 10.01.2025 22:15:23
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
CVE-2022-29155
- EPSS 20.93%
- Veröffentlicht 04.05.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:36
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter ...
CVE-2020-25710
- EPSS 7%
- Veröffentlicht 28.05.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:18:32
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availabil...
CVE-2020-25709
- EPSS 12.34%
- Veröffentlicht 18.05.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:18:32
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
CVE-2021-27212
- EPSS 22.8%
- Veröffentlicht 14.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:36
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to s...
CVE-2020-36230
- EPSS 1.72%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:06
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
CVE-2020-36229
- EPSS 1.98%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:06
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
CVE-2020-36228
- EPSS 66.25%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
CVE-2020-36227
- EPSS 60.34%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
CVE-2020-36226
- EPSS 0.57%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.