← Back

Openldap

openldap

Vendor: Openldap • 59 CVEs

CVEs (59)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Apple
CanonicalDebian+4 more
9Blockchain Platform
Debian LinuxLeap+6 more
Jun 17, 2026
Jul 26, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant de...Show more
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)Show less
4Mcafee
OpenldapOpensuse+1 more
4Blockchain Platform
LeapOpenldap+1 more
May 13, 2026
Dec 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to ca...Show more
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.Show less
2Openldap
Oracle
2Blockchain Platform
Openldap
May 13, 2026
Sep 5, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID fil...Show more
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.Show less
5Debian
McafeeOpenldap+2 more
10Blockchain Platform
Debian LinuxEnterprise Linux Desktop+7 more
May 13, 2026
May 29, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with...Show more
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.Show less
3Openldap
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Hpc Node+6 more
May 6, 2026
Dec 7, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote...Show more
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.Show less
2Apple
Openldap
2Mac Os X
Openldap
May 6, 2026
Sep 11, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by...Show more
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.Show less
2Debian
Openldap
2Debian Linux
Openldap
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
3Apple
OpenldapOpensuse
3Mac Os X
OpenldapOpensuse
May 6, 2026
Feb 12, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.
1Openldap
1Openldap
May 6, 2026
Feb 12, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a...Show more
The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.Show less
2Debian
Openldap
2Debian Linux
Openldap
Apr 29, 2026
Feb 5, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which...Show more
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.Show less
1Openldap
1Openldap
Apr 29, 2026
Jun 29, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.
1Openldap
1Openldap
Apr 29, 2026
Jun 17, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphe...Show more
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.Show less
1Openldap
1Openldap
Apr 29, 2026
Oct 27, 2011
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow,...Show more
Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry.Show less
1Openldap
1Openldap
Apr 29, 2026
Mar 20, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an em...Show more
modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.Show less
1Openldap
1Openldap
Apr 29, 2026
Mar 20, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
1Openldap
1Openldap
Apr 29, 2026
Mar 20, 2011
N/A· v4
N/A· v3
4.6 MEDIUM· v2
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users...Show more
chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.Show less
1Openldap
1Openldap
Apr 29, 2026
Jul 28, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL po...Show more
OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.Show less
4Apple
OpenldapOpensuse+1 more
5Esxi
Mac Os XMac Os X Server+2 more
Apr 29, 2026
Jul 28, 2010
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and po...Show more
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.Show less
3Apple
FedoraprojectOpenldap
3Fedora
Mac Os XOpenldap
Apr 23, 2026
Oct 23, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certifi...Show more
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.Show less
1Openldap
1Openldap
Apr 23, 2026
Jul 1, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.