Red Hat / Directory Server
42 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-18651 | 389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account | MEDIUM | 5.4 | Aug 3, 2026 |
| CVE-2026-11770 | 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check | HIGH | 7.5 | Jul 31, 2026 |
| CVE-2026-15722 | 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing | HIGH | 7.5 | Jul 31, 2026 |
| CVE-2026-15041 | 389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification | LOW | 3.7 | Jul 8, 2026 |
| CVE-2026-14969 | 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption | MEDIUM | 4.4 | Jul 7, 2026 |
| CVE-2026-14940 | 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn | MEDIUM | 5.3 | Jul 7, 2026 |
| CVE-2026-11791 | 389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht() | MEDIUM | 5.0 | Jun 18, 2026 |
| CVE-2026-12528 | 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt() | MEDIUM | 5.4 | Jun 17, 2026 |
| CVE-2026-11790 | 389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service | MEDIUM | 4.9 | Jun 9, 2026 |
| CVE-2026-11789 | 389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash | MEDIUM | 6.5 | Jun 9, 2026 |
| CVE-2026-11788 | 389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser | HIGH | 7.5 | Jun 9, 2026 |
| CVE-2026-11787 | 389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing | MEDIUM | 6.3 | Jun 9, 2026 |
| CVE-2026-11785 | 389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler | MEDIUM | 4.3 | Jun 9, 2026 |
| CVE-2026-11786 | 389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type() | MEDIUM | 6.5 | Jun 9, 2026 |
| CVE-2026-11611 | 389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions | MEDIUM | 6.5 | Jun 8, 2026 |
| CVE-2026-9064 | 389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos) | HIGH | 7.5 | May 20, 2026 |
| CVE-2024-6237 | 389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request | MEDIUM | 6.5 | Jul 9, 2024 |
| CVE-2024-1062 | 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr) | MEDIUM | 5.5 | Feb 12, 2024 |
| CVE-2023-1055 | RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute | MEDIUM | 5.5 | Feb 27, 2023 |
| CVE-2022-2850 | 389-ds-base: SIGSEGV in sync_repl | MEDIUM | 6.5 | Oct 14, 2022 |
| CVE-2022-1949 | 389-ds-base: access control bypass by query (filter in LDAP terms) optimiser | HIGH | 7.5 | Jun 1, 2022 |
| CVE-2020-35518 | 389-ds-base: information disclosure during the binding of a DN | MEDIUM | 5.3 | Mar 26, 2021 |
| CVE-2010-3282 | RHDS/389: information disclosure in audit logs | LOW | 3.3 | Jan 9, 2020 |
| CVE-2010-2222 | redhat-ds/389: null deref in _ger_parse_control() for subjectdn can crash server | HIGH | 7.5 | Nov 5, 2019 |
| CVE-2014-3562 | 389-ds: unauthenticated information disclosure | MEDIUM | 5.0 | Aug 21, 2014 |
Showing 1 to 25 of 42 CVEs