Vulnerabilities
Vulnerable Software
Openldap:  >> Openldap  >> 2.3.29  Security Vulnerabilities
The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.
CVSS Score
4.0
EPSS Score
0.046
Published
2008-02-01
Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.
CVSS Score
5.1
EPSS Score
0.084
Published
2006-12-13
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
CVSS Score
5.0
EPSS Score
0.028
Published
2005-06-30


Contact Us

Shodan ® - All rights reserved