Where
-Infinity
0

redhat Enterprise Linux389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification

Risk 20
Severity
3.7
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption

Risk 26
Severity
4.4
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn

Risk 27
Severity
5.3
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()

Risk 34
Severity
5.4
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise Linux389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()

Risk 38
Severity
6.5
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing

Risk 46
Severity
6.3
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash

Risk 38
Severity
6.5
First published (updated )

redhat Directory Server389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise Linux389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service

Risk 30
Severity
4.9
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()

Risk 35
Severity
5
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)

Risk 31
Severity
7.5
EPSS
0.81%
First published (updated )

redhat Directory Server389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request

Risk 27
Severity
6.5
EPSS
0.07%
First published (updated )

redhat Directory Server389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)

Risk 32
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Fedoraproject 389 Directory Server389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the passw…

Risk 9
Severity
1.2
First published (updated )

Fedoraproject 389 Directory Server389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the passwo…

Risk 13
Severity
2.1
First published (updated )

redhat Directory ServerThe (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.…

Risk 14
Severity
2.1
First published (updated )

redhat Directory ServerBuffer Overflow

Risk 89
Severity
10
First published (updated )

redhat Directory ServerRed Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions fo…

Risk 13
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Directory ServerRed Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properl…

Risk 53
Severity
7.5
First published (updated )

redhat Directory ServerRed Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which all…

Risk 34
Severity
4.6
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203