Directory Server

Vendor:

First CVE: Mar 12, 2008 · Active for 18 years

39
Total CVEs
More Total CVEs than 97% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Directory Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2008
18 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

CVE Severity & Scoring

Directory Server39 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local4 (10.3%)
Network17 (43.6%)
Unknown18 (46.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (48.7%)
High2 (5.1%)
Unknown18 (46.2%)
User Interaction
None21 (53.8%)
Unknown18 (46.2%)
Required0 (0.0%)
Privileges Required
Low11 (28.2%)
High3 (7.7%)
None7 (17.9%)
Unknown18 (46.2%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote
May 20, 20267.533NONO
The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute a
Apr 16, 20089.031NONO
Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and sear
Aug 29, 20087.130NOYES
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote atta
Jun 9, 20267.528NONO
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than
Jun 9, 20266.527NONO
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string f
Jun 9, 20266.327NONO
Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash)
Aug 29, 200810.027NONO
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued n
Jul 7, 20265.326NONO
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causi
Jun 9, 20266.526NONO
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync respon
Jun 8, 20266.526NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Directory Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.2.336.10.7%00
8.236.10.7%00
8.152.71.2%00
8.0144.71.9%01
819.014.0%00
7.1106.84.4%01
13.0135.70.3%00
12.115.50.2%00
12.0185.80.4%00
11.815.50.3%00
11.715.50.3%00
11.615.50.2%00
11.515.50.2%00
11.0155.90.5%00