Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openldap openldap 2.2.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2002-1378
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and previous versions allow remote malicious users to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malic...
Openldap Openldap
7.5
CVSSv2
CVE-2002-1379
OpenLDAP2 (OpenLDAP 2) 2.2.0 and previous versions allows remote or local malicious users to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.
Openldap Openldap
7.1
CVSSv2
CVE-2007-5707
OpenLDAP prior to 2.3.39 allows remote malicious users to cause a denial of service (slapd crash) via an LDAP request with a malformed objectClasses attribute. NOTE: this has been reported as a double free, but the reports are inconsistent.
Openldap Openldap 2.0.2
Openldap Openldap 2.0.11 11
Openldap Openldap 2.1.15
Openldap Openldap 2.1.10
Openldap Openldap 2.3.28 2.20061022
Openldap Openldap 2.2.4
Openldap Openldap 2.2.22
Openldap Openldap 2.1.29
Openldap Openldap 2.2.18
Openldap Openldap 2.1.9
Openldap Openldap 1.2.6
Openldap Openldap 1.1.2
Openldap Openldap 2.0.22
Openldap Openldap 2.0.9
Openldap Openldap 2.2.0
Openldap Openldap 2.1.19
Openldap Openldap 1.0
Openldap Openldap 2.2.29 Rev 1.134
Openldap Openldap 1.2.7
Openldap Openldap 2.2.12
Openldap Openldap 2.2.20
Openldap Openldap 2.0.15
7.1
CVSSv2
CVE-2007-5708
slapo-pcache (overlays/pcache.c) in slapd in OpenLDAP prior to 2.3.39, when running as a proxy-caching server, allocates memory using a malloc variant instead of calloc, which prevents an array from being initialized properly and might allow malicious users to cause a denial of s...
Openldap Openldap 1.1.1
Openldap Openldap 1.1.3
Openldap Openldap 1.2.12
Openldap Openldap 1.2.2
Openldap Openldap 1.2.7
Openldap Openldap 1.2.9
Openldap Openldap 2.0.0
Openldap Openldap 2.0.11 11s
Openldap Openldap 2.0.12
Openldap Openldap 2.0.19
Openldap Openldap 2.0.20
Openldap Openldap 2.0.25
Openldap Openldap 2.0.27
Openldap Openldap 2.0.4
Openldap Openldap 2.0.9
Openldap Openldap 2.1.11
Openldap Openldap 2.1.18
Openldap Openldap 2.1.2
Openldap Openldap 1.2
Openldap Openldap 1.2.0
Openldap Openldap 1.2.1
Openldap Openldap 1.2.10
5.1
CVSSv2
CVE-2006-6493
Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and previous versions, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote malicious users to execute arbitrary code via an LDAP bind request using t...
Openldap Openldap 1.0.3
Openldap Openldap 1.1
Openldap Openldap 1.1.0
Openldap Openldap 1.2.1
Openldap Openldap 1.2.10
Openldap Openldap 1.2.5
Openldap Openldap 1.2.6
Openldap Openldap 2.0.11
Openldap Openldap 2.0.11 11
Openldap Openldap 2.0.16
Openldap Openldap 2.0.17
Openldap Openldap 2.0.23
Openldap Openldap 2.0.24
Openldap Openldap 2.0.7
Openldap Openldap 2.0.8
Openldap Openldap 2.1.15
Openldap Openldap 2.1.16
Openldap Openldap 2.1.22
Openldap Openldap 2.1.23
Openldap Openldap 2.1.30
Openldap Openldap 2.1.4
Openldap Openldap 2.2.0
1 EDB exploit
5
CVSSv2
CVE-2009-1417
gnutls-cli in GnuTLS prior to 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote malicious users to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls...
Gnu Gnutls 1.0.22
Gnu Gnutls 1.0.23
Gnu Gnutls 1.0.24
Gnu Gnutls 1.1.21
Gnu Gnutls 1.1.20
Gnu Gnutls 1.1.15
Gnu Gnutls 1.0.25
Gnu Gnutls 1.2.3
Gnu Gnutls 1.2.2
Gnu Gnutls 1.3.4
Gnu Gnutls 1.2.7
Gnu Gnutls 1.5.0
Gnu Gnutls 1.4.4
Gnu Gnutls 1.6.2
Gnu Gnutls 1.5.5
Gnu Gnutls 1.7.14
Gnu Gnutls 1.7.15
Gnu Gnutls 1.0.18
Gnu Gnutls 1.0.19
Gnu Gnutls 1.1.19
Gnu Gnutls 1.1.16
Gnu Gnutls 1.2.1
4
CVSSv2
CVE-2011-4079
Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and previous versions allows remote malicious users to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddress...
Openldap Openldap 2.0.2
Openldap Openldap 2.0.11 11
Openldap Openldap 2.1.15
Openldap Openldap 2.1.10
Openldap Openldap 2.3.5
Openldap Openldap 2.2.4
Openldap Openldap 2.2.22
Openldap Openldap 2.3.31
Openldap Openldap 2.3.42
Openldap Openldap 2.1.29
Openldap Openldap 2.2.18
Openldap Openldap 2.1.9
Openldap Openldap 1.2.6
Openldap Openldap 1.1.2
Openldap Openldap 2.0.22
Openldap Openldap 2.4.17
Openldap Openldap 2.4.6
Openldap Openldap 2.0.9
Openldap Openldap 2.2.0
Openldap Openldap 2.3.32
Openldap Openldap 2.1.19
Openldap Openldap 1.0
1.2
CVSSv2
CVE-2002-1508
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and previous versions allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.
Openldap Openldap
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started