CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat3389 Directory Server Enterprise LinuxFedoraJun 17, 2026 Mar 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. |
1Redhat 1389 Directory Server Jun 17, 2026 May 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 17, 2026 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP d...Show more |
1Redhat 2389 Directory Server Directory ServerNov 21, 2024 Nov 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query. |
1Redhat 1389 Directory Server Nov 21, 2024 Sep 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort. |