cbcvebase.

Port389 389-Ds-Base vulnerabilities

51 known vulnerabilities affecting port389/389-ds-base.

Total CVEs
51
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH18MEDIUM28LOW3

Vulnerabilities

Page 3 of 3
CVE-2024-2199P4MEDIUMCVSS 5.7≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.3.1+dfsg1-1+deb12u1+1 more2024-05-28
CVE-2024-2199 [MEDIUM] CVE-2024-2199: A denial of service vulnerability was found in 389-ds-base ldap server A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
osv
CVE-2025-2487P4MEDIUMCVSS 4.9≥ 0, < 3.1.2+dfsg1-12025-03-18
CVE-2025-2487 [MEDIUM] CVE-2025-2487: A flaw was found in the 389-ds-base LDAP Server A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.
osv
CVE-2024-5953P4MEDIUMCVSS 5.7≥ 0, < 1.4.4.11-2+deb11u1≥ 0, < 2.3.1+dfsg1-1+deb12u1+1 more2024-06-18
CVE-2024-5953 [MEDIUM] CVE-2024-5953: A denial of service vulnerability was found in the 389-ds-base LDAP server A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
osv
CVE-2013-0312P4MEDIUMCVSS 5.0≥ 0, < 1.3.0.3-12013-03-13
CVE-2013-0312 [MEDIUM] CVE-2013-0312: 389 Directory Server before 1 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.
osv
CVE-2013-2219P4MEDIUMCVSS 4.0≥ 0, < 1.3.2.9-12013-07-31
CVE-2013-2219 [MEDIUM] CVE-2013-2219: The Red Hat Directory Server before 8 The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.
osv
CVE-2019-10224P4MEDIUMCVSS 4.6≥ 0, < 1.4.1.5-12019-11-25
CVE-2019-10224 [MEDIUM] CVE-2019-10224: A flaw has been found in 389-ds-base versions 1 A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
osv
CVE-2014-8112P4MEDIUMCVSS 4.0≥ 0, < 1.3.3.5-42015-03-10
CVE-2014-8112 [MEDIUM] CVE-2014-8112: 389 Directory Server 1 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
osv
CVE-2012-2678P4LOWCVSS 1.2≥ 0, < 1.3.2.16-0ubuntu12012-07-03
CVE-2012-2678 [LOW] CVE-2012-2678: 389 Directory Server before 1 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
osv
CVE-2013-4485P4MEDIUMCVSS 4.0≥ 0, < 1.3.2.9-12013-11-23
CVE-2013-4485 [MEDIUM] CVE-2013-4485: 389 Directory Server 1 389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.
osv
CVE-2013-1897P4LOWCVSS 2.6≥ 0, < 1.3.2.9-12013-05-13
CVE-2013-1897 [LOW] CVE-2013-1897: The do_search function in ldap/servers/slapd/search The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.
osv
CVE-2012-2746P4LOWCVSS 2.1≥ 0, < 1.3.2.16-0ubuntu12012-07-03
CVE-2012-2746 [LOW] CVE-2012-2746: 389 Directory Server before 1 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.
osv
Port389 389-Ds-Base vulnerabilities | cvebase