Openldap

Openldap

59 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.7%
  • Published 26.01.2021 18:15:57
  • Last modified 21.11.2024 05:29:05

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

  • EPSS 47.65%
  • Published 26.01.2021 18:15:56
  • Last modified 21.11.2024 05:29:04

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

  • EPSS 29.74%
  • Published 26.01.2021 18:15:56
  • Last modified 21.11.2024 05:29:04

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.

  • EPSS 0.78%
  • Published 26.01.2021 18:15:56
  • Last modified 21.11.2024 05:29:04

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

  • EPSS 6.01%
  • Published 26.01.2021 18:15:56
  • Last modified 21.11.2024 05:29:04

A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).

  • EPSS 0.65%
  • Published 08.12.2020 01:15:12
  • Last modified 21.11.2024 05:18:29

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial ...

  • EPSS 0.14%
  • Published 14.07.2020 14:15:17
  • Last modified 21.11.2024 05:06:05

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openl...

Exploit
  • EPSS 6.57%
  • Published 28.04.2020 19:15:12
  • Last modified 21.11.2024 04:59:22

In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

Exploit
  • EPSS 5.15%
  • Published 02.01.2020 23:15:11
  • Last modified 21.11.2024 02:18:43

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

  • EPSS 1.14%
  • Published 26.07.2019 13:15:12
  • Last modified 21.11.2024 04:24:07

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not pro...