Search CVE reports


Toggle filters

31 – 40 of 53 results


CVE-2017-15134

Medium priority

Some fixes available 1 of 3

A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2017-15135

Medium priority
Ignored

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-1854

Medium priority
Ignored

389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected
Show less packages

CVE-2017-7551

Medium priority
Vulnerable

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-5416

Low priority
Ignored

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2016-5405

Low priority
Ignored

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected
Show less packages

CVE-2016-4992

Low priority
Vulnerable

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-0741

Medium priority

Some fixes available 1 of 9

slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected Not affected Not affected
Show less packages

CVE-2015-3230

Medium priority

Some fixes available 1 of 5

389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Fixed
Show less packages

CVE-2014-8112

Low priority
Ignored

389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain...

1 affected package

389-ds-base

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
389-ds-base Not affected Not affected
Show less packages