📦

openldap

Vendor: openldap

Actively Exploited 0 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 3 Remote Access
Total CVEs 129 Total Indexed
Avg. EPSS 15.46% Exploit Prob.
Latest CVE CVE-2023-2953 May 30

Security Vulnerability Index

Page 1 / 13
7.5 CVSS

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

EPSS: 1.42%
9.8 CVSS

In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.

EPSS: 13.61%
7.5 CVSS

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

EPSS: 17.46%
7.5 CVSS

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.

EPSS: 35.68%
7.5 CVSS

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to schema_init.c and checkTime.

EPSS: 25.12%
7.5 CVSS

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

EPSS: 3.55%
7.5 CVSS

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.

EPSS: 4.95%
7.5 CVSS

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.

EPSS: 71.52%
7.5 CVSS

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.

EPSS: 63.63%
7.5 CVSS

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

EPSS: 1.07%