Vulnerabilities > Openldap

DATE CVE VULNERABILITY TITLE RISK
2022-05-04 CVE-2022-29155 SQL Injection vulnerability in Openldap
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query.
network
low complexity
openldap CWE-89
7.5
2021-05-28 CVE-2020-25710 Reachable Assertion vulnerability in multiple products
A flaw was found in OpenLDAP in versions before 2.4.56.
network
low complexity
openldap redhat debian fedoraproject CWE-617
5.0
2021-05-18 CVE-2020-25709 Reachable Assertion vulnerability in multiple products
A flaw was found in OpenLDAP.
network
low complexity
openldap debian apple redhat CWE-617
5.0
2021-02-14 CVE-2021-27212 Reachable Assertion vulnerability in multiple products
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp.
network
low complexity
openldap debian CWE-617
5.0
2021-01-26 CVE-2020-36230 Reachable Assertion vulnerability in multiple products
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
network
low complexity
openldap debian apple apache CWE-617
5.0
2021-01-26 CVE-2020-36229 Type Confusion vulnerability in multiple products
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
network
low complexity
openldap debian apple CWE-843
5.0
2021-01-26 CVE-2020-36228 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
network
low complexity
openldap debian apple CWE-191
5.0
2021-01-26 CVE-2020-36227 Infinite Loop vulnerability in multiple products
A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.
network
low complexity
openldap debian apple CWE-835
5.0
2021-01-26 CVE-2020-36226 A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.
network
low complexity
openldap debian apple
5.0
2021-01-26 CVE-2020-36225 Double Free vulnerability in multiple products
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
network
low complexity
openldap debian apple CWE-415
5.0