CVE-2018-10935
CVE-2018-10935 is a medium-severity vulnerability in Redhat 389 Directory Server with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 4.0
- EPSS exploit prediction: 2% (78th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Redhat 389 Directory Server
- Published:
- Last modified:
Description
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
Frequently asked questions
- What is CVE-2018-10935?
- A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
- How severe is CVE-2018-10935?
- CVE-2018-10935 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2018-10935 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (78th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-10935?
- CVE-2018-10935 affects Redhat 389 Directory Server. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-10935?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2018-10935 published?
- CVE-2018-10935 was published on 2018-09-11 and last updated on 2026-06-17.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00033.html
- https://access.redhat.com/errata/RHSA-2018:2757
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10935
- https://lists.debian.org/debian-lts-announce/2018/08/msg00032.html
Affected products (1)
- cpe:2.3:o:redhat:389_directory_server:*:*:*:*:*:*:*:*
More vulnerabilities in Redhat 389 Directory Server
- CVE-2026-15722 — High (CVSS 7.5): A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function…
- CVE-2026-11770 — High (CVSS 7.5): A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the…
- CVE-2026-9064 — High (CVSS 7.5): A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an…
- CVE-2022-1949 — High (CVSS 7.5): An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect…
- CVE-2010-2222 — High (CVSS 7.5): The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a…
- CVE-2026-11611 — Medium (CVSS 6.5): A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory…
All CVEs affecting Redhat 389 Directory Server →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-93952 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-77554 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-77537 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →