Vulnerabilities > Redhat > 389 Directory Server

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2022-0996 Improper Authentication vulnerability in multiple products
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
network
low complexity
redhat fedoraproject CWE-287
6.5
2021-05-28 CVE-2021-3514 Unspecified vulnerability in Redhat 389 Directory Server
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
network
low complexity
redhat
6.5
2021-03-26 CVE-2020-35518 Information Exposure Through Discrepancy vulnerability in Redhat 389 Directory Server
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not.
network
low complexity
redhat CWE-203
5.0
2019-11-05 CVE-2010-2222 NULL Pointer Dereference vulnerability in Redhat 389 Directory Server and Directory Server
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
network
low complexity
redhat CWE-476
5.0
2018-09-11 CVE-2018-10935 Improper Input Validation vulnerability in Redhat 389 Directory Server
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
network
low complexity
redhat CWE-20
4.0