CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 9, 2026 Jul 8, 2026 N/A· v4 3.7 LOW· v3 N/A· v2 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could pote...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 9, 2026 Jul 7, 2026 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to det...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 9, 2026 Jul 7, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN),...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 18, 2026 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere i...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 28, 2026 Jun 17, 2026 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing....Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a use...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read tha...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the s...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence interna...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable unde...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 23, 2026 Jun 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additio...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 23, 2026 May 20, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a sp...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 17, 2026 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. |
2Fedoraproject Redhat13389 Directory Server Directory ServerEnterprise Linux+10 moreJun 17, 2026 Feb 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. |
2Fedoraproject Redhat2Directory Server FedoraJun 17, 2026 Feb 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker wit...Show more |
4Debian FedoraprojectPort389+1 more5389 Ds Base Debian LinuxDirectory Server+2 moreJun 17, 2026 Oct 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker...Show more |
2Fedoraproject Redhat4389 Directory Server Directory ServerEnterprise Linux+1 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass....Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 17, 2026 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP d...Show more |
3Fedoraproject HpRedhat4389 Directory Server Directory ServerHp Ux Directory Server+1 moreNov 21, 2024 Jan 9, 2020 N/A· v4 3.3 LOW· v3 1.9 LOW· v2 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when c...Show more |