CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject HpRedhat4389 Directory Server Directory ServerHp Ux Directory Server+1 moreNov 21, 2024 Jan 9, 2020 N/A· v4 3.3 LOW· v3 1.9 LOW· v2 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when c...Show more |
1Fedoraproject 1389 Directory Server Nov 21, 2024 Nov 25, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker...Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxNov 21, 2024 Nov 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more |
2Fedoraproject Redhat2389 Directory Server Enterprise Linux Server EusNov 21, 2024 Aug 2, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial...Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxNov 21, 2024 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests....Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxNov 21, 2024 Sep 28, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of servi...Show more |
2Fedoraproject Redhat7389 Directory Server Enterprise Linux AusEnterprise Linux Desktop+4 moreNov 21, 2024 Sep 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service. |
3Debian FedoraprojectRedhat8389 Directory Server Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Sep 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker...Show more |
2Debian Fedoraproject2389 Directory Server Debian LinuxNov 21, 2024 Jul 18, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plainte...Show more |
2Fedoraproject Redhat4389 Directory Server Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jun 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash vi...Show more |
3Debian FedoraprojectRedhat9389 Directory Server Debian LinuxEnterprise Linux+6 moreNov 21, 2024 Jun 13, 2018 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this fla...Show more |
3Debian FedoraprojectRedhat5389 Directory Server Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 May 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potential...Show more |
1Fedoraproject 1389 Directory Server Nov 21, 2024 May 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request. |
2Fedoraproject Redhat2389 Directory Server Enterprise LinuxNov 21, 2024 Apr 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possib...Show more |
2Fedoraproject Redhat4389 Directory Server Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Mar 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make n...Show more |
2Fedoraproject Redhat5389 Directory Server Enterprise LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Mar 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentiall...Show more |
1Fedoraproject 1389 Directory Server Nov 21, 2024 Jan 24, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could pote...Show more |
2Debian Fedoraproject3389 Directory Server Debian LinuxFedoraMay 13, 2026 Sep 19, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call. |
1Fedoraproject 1389 Directory Server May 13, 2026 Aug 16, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts. |
2Fedoraproject Redhat6389 Directory Server Enterprise LinuxEnterprise Linux Desktop+3 moreMay 6, 2026 Apr 19, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormall...Show more |