VYPR
Vendor

389 Ds Base

Products
1
CVEs
24
Across products
24
Status
Private

Products

1

Recent CVEs

24
View all 24 CVEs →
  • CVE-2026-11610impJul 7, 2026
    risk 0.57cvss 8.8epss 0.01

    389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND

  • CVE-2026-15722impJul 31, 2026
    risk 0.49cvss 7.5epss 0.01

    389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing

  • CVE-2026-11770modJul 31, 2026
    risk 0.49cvss 7.5epss 0.01

    389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check

  • CVE-2024-3657HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

  • CVE-2022-1949HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a…

  • CVE-2021-4091HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.02

    A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

  • CVE-2019-3883HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.08

    In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into…

  • CVE-2018-14624HigSep 6, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN,…

  • CVE-2018-1054HigMar 7, 2018
    risk 0.49cvss 7.5epss 0.05

    An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus…

  • CVE-2017-15134HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.04

    A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially…

  • CVE-2022-2850MedOct 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against…

  • CVE-2019-14824MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

  • CVE-2018-10850MedJun 13, 2018
    risk 0.38cvss 5.9epss 0.02

    389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.

  • CVE-2024-8445MedSep 5, 2024
    risk 0.37cvss 5.7epss 0.00

    The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.

  • CVE-2024-5953MedJun 18, 2024
    risk 0.37cvss 5.7epss 0.01

    A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.

  • CVE-2024-2199MedMay 28, 2024
    risk 0.37cvss 5.7epss 0.01

    A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.

  • CVE-2024-1062MedFeb 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

  • CVE-2026-12528lowJun 3, 2026
    risk 0.35cvss 5.4epss 0.00

    389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()

  • CVE-2026-16560modJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued RDN

  • CVE-2026-14940modJul 7, 2026
    risk 0.34cvss 5.3epss 0.00

    389-ds-base: 389-ds-base: heap-buffer-overflow in DN normalization via quoted multivalued RDN