Fedoraproject
Fedoraproject 389 Directory Server: vulnerabilidades y CVE
Fedoraproject 389 Directory Server tiene 39 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2010-3282 | Baja (3.3) | 0.26% | — | 9 ene 2020 | 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when… |
| CVE-2019-10224 | Media (4.6) | 0.40% | — | 25 nov 2019 | A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An… |
| CVE-2019-14824 | Media (6.5) | 1.3% | — | 8 nov 2019 | A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private… |
| CVE-2019-10171 | Alta (7.5) | 1.4% | — | 2 ago 2019 | It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a… |
| CVE-2019-3883 | Alta (7.5) | 8.2% | — | 17 abr 2019 | In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests.… |
| CVE-2018-14648 | Alta (7.5) | 6.3% | — | 28 sept 2018 | A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of… |
| CVE-2018-14638 | Alta (7.5) | 2.6% | — | 14 sept 2018 | A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service. |
| CVE-2018-14624 | Alta (7.5) | 2.5% | — | 6 sept 2018 | A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An… |
| CVE-2018-10871 | Alta (7.2) | 1.1% | — | 18 jul 2018 | 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in… |
| CVE-2017-2668 | Media (6.5) | 2.6% | — | 22 jun 2018 | 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash… |
| CVE-2018-10850 | Media (5.9) | 1.6% | — | 13 jun 2018 | 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this… |
| CVE-2018-1089 | Alta (7.5) | 4.1% | — | 9 may 2018 | 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could… |
| CVE-2011-0704 | Media (5.9) | 1.2% | — | 4 may 2018 | 389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request. |
| CVE-2017-2591 | Alta (7.5) | 2.9% | — | 30 abr 2018 | 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or… |
| CVE-2018-1054 | Alta (7.5) | 4.6% | — | 7 mar 2018 | An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make… |
| CVE-2017-15134 | Alta (7.5) | 3.9% | — | 1 mar 2018 | A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could… |
| CVE-2017-15135 | Alta (8.1) | 3.8% | — | 24 ene 2018 | It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could… |
| CVE-2015-1854 | Alta (7.5) | 2.1% | — | 19 sept 2017 | 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call. |
| CVE-2017-7551 | Crítica (9.8) | 1.4% | — | 16 ago 2017 | 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts. |
| CVE-2016-0741 | Alta (7.5) | 4.0% | — | 19 abr 2016 | slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an… |
| CVE-2015-3230 | Alta (7.5) | 2.6% | — | 29 oct 2015 | 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to… |
| CVE-2014-8112 | Media (4) | 1.7% | — | 10 mar 2015 | 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to… |
| CVE-2014-8105 | Media (5) | 2.1% | — | 10 mar 2015 | 389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via… |
| CVE-2014-3562 | Media (5) | 2.2% | — | 21 ago 2014 | Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. |
| CVE-2014-0132 | Media (6.5) | 2.2% | — | 18 mar 2014 | The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind. |
| CVE-2013-4485 | Media (4) | 2.0% | — | 23 nov 2013 | 389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request. |
| CVE-2013-4283 | Media (5) | 2.4% | — | 10 sept 2013 | ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request. |
| CVE-2013-2219 | Media (4) | 1.8% | — | 31 jul 2013 | The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for… |
| CVE-2013-1897 | Baja (2.6) | 2.1% | — | 13 may 2013 | The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access… |
| CVE-2013-0312 | Media (5) | 2.7% | — | 13 mar 2013 | 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence. |