Skip to main content

Vendor/product archive

fedoraproject / 389_directory_server CVEs

Beta · best-effort

39 CVEs tagged to fedoraproject / 389_directory_server1 Critical, 13 High, 18 Medium, 7 Low, 0 Unrated.

CVE-2019-10224

Published Nov 25, 2019

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as th…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14638

Published Sep 14, 2018

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpecte…

CVSS 7.5 · High

CVE-2018-14624

Published Sep 6, 2018

A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log fi…

CVSS 7.5 · High

CVE-2018-10850

Published Jun 13, 2018

389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load.…

CVSS 5.9 · Medium

CVE-2011-0704

Published May 4, 2018

389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15135

Published Jan 24, 2018

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A re…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7551

Published Aug 16, 2017

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3230

Published Oct 29, 2015

389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0132

Published Mar 18, 2014

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2