389 Directory Server

Vendor:

First CVE: Sep 11, 2018 · Active for 7 years

22
Total CVEs
More Total CVEs than 94% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact 389 Directory Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2018
7 years ago
Most Recent CVE
Jul 8, 2026
19 days ago

CVE Severity & Scoring

389 Directory Server22 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local2 (9.1%)
Network20 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (50.0%)
High4 (18.2%)
None7 (31.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote
May 20, 20267.533NONO
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote atta
Jun 9, 20267.528NONO
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than
Jun 9, 20266.527NONO
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string f
Jun 9, 20266.327NONO
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued n
Jul 7, 20265.326NONO
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causi
Jun 9, 20266.526NONO
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync respon
Jun 8, 20266.526NONO
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted se
Nov 5, 20197.525NONO
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time compariso
Jul 8, 20263.724NONO
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without b
Jun 9, 20264.924NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For 389 Directory Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.4.0.016.51.5%00
1.3.6.014.90.3%00