CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectPort389+1 more5389 Ds Base Debian LinuxDirectory Server+2 moreNov 3, 2025 Oct 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker...Show more |
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw al...Show more |
2Port389 Redhat2389 Ds Base Enterprise LinuxNov 3, 2025 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message...Show more |
2Port389 Redhat8389 Ds Base Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+5 moreNov 3, 2025 Feb 18, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash. |