389-ds-base:
This hub aggregates every CVE we track for 389-ds-base:. Use it to gauge the current risk picture and drill into individual advisories.
other
24
CVEs tracked
1
Critical
12
High
0
In CISA KEV
Severity distribution
HIGH12MEDIUM9LOW2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting 389-ds-base:.
- CVE-2026-11610389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded sasl unbind8.8
- CVE-2025-2487389-ds-base: null pointer dereference leads to denial of service4.9
- CVE-2024-5953389-ds-base: malformed userpassword hash may cause denial of service5.7
- CVE-2022-2850A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an ...6.5
- CVE-2021-3652A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authe...6.5
- CVE-2022-0918A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is trigge...7.5
- CVE-2021-4091A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpected...7.5
- CVE-2019-10224A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manage...4.6
- CVE-2019-14824A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to v...6.5
- CVE-2019-10171It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumpt...7.5
- CVE-2019-3883In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for ...7.5
- CVE-2018-14648A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to pr...7.5
- CVE-2018-14638A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to rem...7.5
- CVE-2018-10935A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.6.5
- CVE-2018-14624A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_e...7.5
Product normalization is registry-driven with AI assist and human review. How it works