CVE-2020-36226
- EPSS 0.64%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVE-2020-36225
- EPSS 0.87%
- Veröffentlicht 26.01.2021 18:15:57
- Zuletzt bearbeitet 21.11.2024 05:29:05
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVE-2020-36222
- EPSS 27.19%
- Veröffentlicht 26.01.2021 18:15:56
- Zuletzt bearbeitet 21.11.2024 05:29:04
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
CVE-2020-36221
- EPSS 47.65%
- Veröffentlicht 26.01.2021 18:15:56
- Zuletzt bearbeitet 21.11.2024 05:29:04
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).
CVE-2020-36223
- EPSS 6.67%
- Veröffentlicht 26.01.2021 18:15:56
- Zuletzt bearbeitet 21.11.2024 05:29:04
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).
CVE-2020-36224
- EPSS 0.87%
- Veröffentlicht 26.01.2021 18:15:56
- Zuletzt bearbeitet 21.11.2024 05:29:04
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
CVE-2020-25692
- EPSS 1.22%
- Veröffentlicht 08.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:29
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial ...
CVE-2020-15719
- EPSS 0.22%
- Veröffentlicht 14.07.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:06:05
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openl...
CVE-2020-12243
- EPSS 10.76%
- Veröffentlicht 28.04.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:22
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
CVE-2014-8182
- EPSS 5.15%
- Veröffentlicht 02.01.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 02:18:43
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.