cbcvebase.

Redhat Directory Server vulnerabilities

39 known vulnerabilities affecting redhat/directory_server.

Total CVEs
39
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH9MEDIUM22LOW6

Vulnerabilities

Page 1 of 2
CVE-2008-0892P3CRITICALCVSS 9.0v7.1v82008-04-16
CVE-2008-0892 [CRITICAL] CWE-20 CVE-2008-0892: The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used b The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.
nvd
CVE-2008-2930P4HIGHCVSS 7.1PoCv7.1v8.02008-08-29
CVE-2008-2930 [HIGH] CWE-399 CVE-2008-2930: Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1 Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.
nvd
CVE-2026-9064P3HIGHCVSS 7.5v11.0v12.0+1 more2026-05-20
CVE-2026-9064 [HIGH] CWE-770 CVE-2026-9064: A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), c
nvd
CVE-2022-1949P3HIGHCVSS 7.5v11.0v12.02022-06-02
CVE-2022-1949 [HIGH] CWE-639 CVE-2022-1949: An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that wou An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, i
nvd
CVE-2026-11788P3HIGHCVSS 7.5v11.0v12.0+1 more2026-06-09
CVE-2026-11788 [HIGH] CWE-476 CVE-2026-11788: A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocati A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
nvd
CVE-2008-2928P3CRITICALCVSS 10.0v7.12008-08-29
CVE-2008-2928 [CRITICAL] CWE-119 CVE-2008-2928: Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7 Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted Accept-Language HTTP header.
nvd
CVE-2008-0893P3HIGHCVSS 7.5v8.02008-04-16
CVE-2008-0893 [HIGH] CWE-264 CVE-2008-0893: Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properl Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions.
nvd
CVE-2026-11789P3MEDIUMCVSS 6.5v11.0v12.0+1 more2026-06-09
CVE-2026-11789 [MEDIUM] CWE-191 CVE-2026-11789: A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
nvd
CVE-2008-1677P3HIGHCVSS 7.5v7.1v8.02008-05-12
CVE-2008-1677 [HIGH] CWE-120 CVE-2008-1677: Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LDAP query that triggers the overflow during translation to a regular expression.
nvd
CVE-2026-11786P3MEDIUMCVSS 6.5v11.0v12.0+1 more2026-06-09
CVE-2026-11786 [MEDIUM] CWE-125 CVE-2026-11786: A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when p A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.
nvd
CVE-2026-11787P3MEDIUMCVSS 6.3v11.0v12.0+1 more2026-06-09
CVE-2026-11787 [MEDIUM] CWE-126 CVE-2026-11787: A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
nvd
CVE-2026-11611P3MEDIUMCVSS 6.5v11.0v12.0+1 more2026-06-08
CVE-2026-11611 [MEDIUM] CWE-400 CVE-2026-11611: A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allow A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or shutdown.
nvd
CVE-2024-6237P4MEDIUMCVSS 6.5v12.02024-07-09
CVE-2024-6237 [MEDIUM] CWE-230 CVE-2024-6237: A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a sy A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.
nvd
CVE-2008-3283P4HIGHCVSS 7.8v7.1v8.02008-08-29
CVE-2008-3283 [HIGH] CWE-399 CVE-2008-3283: Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fe Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.
nvd
CVE-2020-35518P4MEDIUMCVSS 5.3v11.02021-03-26
CVE-2020-35518 [MEDIUM] CWE-200 CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whethe When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
nvd
CVE-2026-12528P4MEDIUMCVSS 5.4v11.0v12.0+1 more2026-06-17
CVE-2026-12528 [MEDIUM] CWE-787 CVE-2026-12528: A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-b
nvd
CVE-2010-2222P4HIGHCVSS 7.5v8.02019-11-05
CVE-2010-2222 [HIGH] CWE-476 CVE-2010-2222: The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows at The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
nvd
CVE-2026-14940P4MEDIUMCVSS 5.3v11.0v12.0+1 more2026-07-07
CVE-2026-14940 [MEDIUM] CWE-122 CVE-2026-14940: A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Dist A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An unauthenticated remote attacker
nvd
CVE-2022-2850P4MEDIUMCVSS 6.5v11.0v12.02022-10-14
CVE-2022-2850 [MEDIUM] CVE-2022-2850: A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticate A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
nvd
CVE-2011-0019P4HIGHCVSS 7.5v8.2v8.2.32011-02-23
CVE-2011-0019 [HIGH] CWE-20 CVE-2011-0019: slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.
nvd
Redhat Directory Server vulnerabilities | cvebase