Show filters
60 Total Results
Displaying 1-10 of 60
Sort by:
Attacker Value
Unknown

CVE-2013-4449

Disclosure Date: February 05, 2014 (last updated October 05, 2023)
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.
1
Attacker Value
Unknown

CVE-2023-2953

Disclosure Date: May 30, 2023 (last updated October 08, 2023)
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Attacker Value
Unknown

CVE-2022-29155

Disclosure Date: May 04, 2022 (last updated October 07, 2023)
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
Attacker Value
Unknown

CVE-2020-25710

Disclosure Date: May 28, 2021 (last updated November 08, 2023)
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-25709

Disclosure Date: May 18, 2021 (last updated November 08, 2023)
A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-27212

Disclosure Date: February 14, 2021 (last updated November 08, 2023)
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.
Attacker Value
Unknown

CVE-2020-36226

Disclosure Date: January 26, 2021 (last updated November 08, 2023)
A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
Attacker Value
Unknown

CVE-2020-36224

Disclosure Date: January 26, 2021 (last updated November 08, 2023)
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
Attacker Value
Unknown

CVE-2020-36230

Disclosure Date: January 26, 2021 (last updated November 08, 2023)
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
Attacker Value
Unknown

CVE-2020-36229

Disclosure Date: January 26, 2021 (last updated November 08, 2023)
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.