Show filters
60 Total Results
Displaying 41-50 of 60
Sort by:
Attacker Value
Unknown
CVE-2008-2952
Disclosure Date: July 01, 2008 (last updated October 04, 2023)
liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.
0
Attacker Value
Unknown
CVE-2008-0658
Disclosure Date: February 13, 2008 (last updated October 04, 2023)
slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.
0
Attacker Value
Unknown
CVE-2007-6698
Disclosure Date: February 01, 2008 (last updated October 04, 2023)
The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.
0
Attacker Value
Unknown
CVE-2007-5708
Disclosure Date: October 30, 2007 (last updated October 04, 2023)
slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP before 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow attackers to cause a denial of service (segmentation fault) via unknown vectors that prevent the array from being null terminated.
0
Attacker Value
Unknown
CVE-2007-5707
Disclosure Date: October 30, 2007 (last updated November 08, 2023)
OpenLDAP before 2.3.39 allows remote attackers to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute. NOTE: this has been reported as a double free, but the reports are inconsistent.
0
Attacker Value
Unknown
CVE-2006-6493
Disclosure Date: December 13, 2006 (last updated October 04, 2023)
Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.
0
Attacker Value
Unknown
CVE-2006-5779
Disclosure Date: November 07, 2006 (last updated February 08, 2024)
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
0
Attacker Value
Unknown
CVE-2006-4600
Disclosure Date: September 07, 2006 (last updated October 04, 2023)
slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).
0
Attacker Value
Unknown
CVE-2006-2754
Disclosure Date: June 01, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code via a long hostname.
0
Attacker Value
Unknown
CVE-2005-4442
Disclosure Date: December 21, 2005 (last updated February 22, 2025)
Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
0