cbcvebase.

Port389 389-Ds-Base vulnerabilities

51 known vulnerabilities affecting port389/389-ds-base.

Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM28LOW3

Vulnerabilities

Page 2 of 3
CVE-2018-14638P3HIGHCVSS 7.5≥ 0, < 1.4.0.18-12018-09-14
CVE-2018-14638 [HIGH] CVE-2018-14638: A flaw was found in 389-ds-base before version 1 A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
osv
CVE-2018-14624P3HIGHCVSS 7.5≥ 0, < 1.4.0.18-12018-09-06
CVE-2018-14624 [HIGH] CVE-2018-14624: A vulnerability was discovered in 389-ds-base through versions 1 A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.
osv
CVE-2016-0741P3HIGHCVSS 7.5≥ 0, < 1.3.4.8-12016-04-19
CVE-2016-0741 [HIGH] CVE-2016-0741: slapd/connection slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
osv
CVE-2019-14824P3MEDIUMCVSS 6.5≥ 0, < 1.4.2.4-12019-11-08
CVE-2019-14824 [MEDIUM] CVE-2019-14824: A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
osv
CVE-2021-3514P4MEDIUMCVSS 6.5≥ 0, < 1.4.4.11-22021-05-28
CVE-2021-3514 [MEDIUM] CVE-2021-3514: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
osv
CVE-2024-6237P4MEDIUMCVSS 6.5≥ 0, < 2.4.5+dfsg1-12024-07-09
CVE-2024-6237 [MEDIUM] CVE-2024-6237: A flaw was found in the 389 Directory Server A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
osv
CVE-2020-35518P4MEDIUMCVSS 5.3≥ 0, < 1.4.4.10-12021-03-26
CVE-2020-35518 [MEDIUM] CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
osv
CVE-2017-2668P4MEDIUMCVSS 6.5≥ 0, < 1.3.5.17-12018-06-22
CVE-2017-2668 [MEDIUM] CVE-2017-2668: 389-ds-base before versions 1 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
osv
CVE-2012-4450P4MEDIUMCVSS 6.0≥ 0, < 1.2.11.15-12012-10-01
CVE-2012-4450 [MEDIUM] CVE-2012-4450: 389 Directory Server 1 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
osv
CVE-2018-10935P4MEDIUMCVSS 6.5≥ 0, < 1.4.0.15-12018-09-11
CVE-2018-10935 [MEDIUM] CVE-2018-10935: A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
osv
CVE-2022-2850P4MEDIUMCVSS 6.5≥ 2.0.0, ≤ 2.4.12022-10-14
CVE-2022-2850 [MEDIUM] CVE-2022-2850: A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticate A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
nvdosv
CVE-2018-10850P4MEDIUMCVSS 5.9≥ 0, < 1.4.0.15-12018-06-13
CVE-2018-10850 [MEDIUM] CVE-2018-10850: 389-ds-base before versions 1 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.
osv
CVE-2011-0704P4MEDIUMCVSS 5.9≥ 0, < 1.3.7.10-1ubuntu1≥ 0, < 1.4.3.6-2+1 more2018-05-04
CVE-2011-0704 [MEDIUM] CVE-2011-0704: 389 Directory Server 1 389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.
osv
CVE-2014-3562P4MEDIUMCVSS 5.0≥ 0, < 1.3.2.21-12014-08-21
CVE-2014-3562 [MEDIUM] CVE-2014-3562: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by sea Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
osv
CVE-2014-8105P4MEDIUMCVSS 5.0≥ 0, < 1.3.3.5-42015-03-10
CVE-2014-8105 [MEDIUM] CVE-2014-8105: 389 Directory Server before 1 389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
osv
CVE-2023-1055P4MEDIUMCVSS 5.5≥ 0, < 2.3.4+dfsg1-12023-02-27
CVE-2023-1055 [MEDIUM] CVE-2023-1055: A flaw was found in RHDS 11 and RHDS 12 A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
osv
CVE-2013-0336P4MEDIUMCVSS 5.0≥ 0, < 1.3.2.9-12014-11-03
CVE-2013-0336 [MEDIUM] CVE-2013-0336: The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.
osv
CVE-2013-4283P4MEDIUMCVSS 5.0≥ 0, < 1.3.2.9-12013-09-10
CVE-2013-4283 [MEDIUM] CVE-2013-4283: ns-slapd in 389 Directory Server before 1 ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.
osv
CVE-2024-8445P4MEDIUMCVSS 5.7≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.0.11-12024-09-05
CVE-2024-8445 [MEDIUM] CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
osv
CVE-2024-1062P4MEDIUMCVSS 5.5≥ 0, < 2.3.4+dfsg1-12024-02-12
CVE-2024-1062 [MEDIUM] CVE-2024-1062: A heap overflow flaw was found in 389-ds-base A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
osv
Port389 389-Ds-Base vulnerabilities | cvebase