VendorsRed Hatdirectory_server13.0
Vulnerabilities

Red Hat Directory Server 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-9064
389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
Published 2026-05-20 · Modified
7.5EPSS 0.011
CVE-2026-11788
389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser
Published 2026-06-09 · Modified
7.5EPSS 0.006
CVE-2026-11770
389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
Published 2026-07-31 · Modified
7.5EPSS 0.005
CVE-2026-11789
389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash
Published 2026-06-09 · Modified
6.5EPSS 0.003
CVE-2026-11611
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
Published 2026-06-08 · Modified
6.5EPSS 0.002
CVE-2026-11786
389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()
Published 2026-06-09 · Modified
6.5EPSS 0.002
CVE-2026-11787
389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing
Published 2026-06-09 · Modified
6.3EPSS 0.002
CVE-2026-18651
389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
Published 2026-08-03 · Analyzed
5.4EPSS 0.003
CVE-2026-12528
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
Published 2026-06-17 · Analyzed
5.4EPSS 0.002
CVE-2026-14940
389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
Published 2026-07-07 · Analyzed
5.3EPSS 0.005
CVE-2026-11791
389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()
Published 2026-06-18 · Modified
5.0EPSS 0.004
CVE-2026-11790
389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service
Published 2026-06-09 · Modified
4.9EPSS 0.003
CVE-2026-14969
389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption
Published 2026-07-07 · Analyzed
4.4EPSS 0.001
CVE-2026-11785
389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler
Published 2026-06-09 · Modified
4.3EPSS 0.002
CVE-2026-15041
389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
Published 2026-07-08 · Analyzed
3.7EPSS 0.004