cbcvebase.

Ibm Tivoli Directory Server vulnerabilities

43 known vulnerabilities affecting ibm/tivoli_directory_server.

Total CVEs
43
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM34LOW4

Vulnerabilities

Page 2 of 3
CVE-2015-1978P4MEDIUMCVSS 4.3v6.0v6.1.0+4 more2015-06-28
CVE-2015-1978 [MEDIUM] CWE-79 CVE-2015-1978: Cross-site scripting (XSS) vulnerability in IBM Tivoli Security Directory Server 6.0 before iFix 75, Cross-site scripting (XSS) vulnerability in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-3090P4MEDIUMCVSS 5.0v6.02009-09-08
CVE-2009-3090 [MEDIUM] CVE-2009-3090: Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, t
nvd
CVE-2015-1972P4MEDIUMCVSS 4.3v6.0v6.1.0+4 more2015-06-28
CVE-2015-1972 [MEDIUM] CWE-200 CVE-2015-1972: IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request.
nvd
CVE-2012-0740P4MEDIUMCVSS 4.3v6.2v6.2.0.19+7 more2012-04-22
CVE-2012-0740 [MEDIUM] CWE-79 CVE-2012-0740: Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) Cross-site scripting (XSS) vulnerability in the Web Admin Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.22 and 6.3 before 6.3.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2010-4216P4MEDIUMCVSS 5.0v6.0v6.0.0.7+1 more2010-11-09
CVE-2010-4216 [MEDIUM] CWE-119 CVE-2010-4216: IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.
nvd
CVE-2008-7288P4MEDIUMCVSS 5.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7288 [MEDIUM] CWE-399 CVE-2008-7288: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
nvd
CVE-2015-1959P4MEDIUMCVSS 4.6v6.0v6.1.0+4 more2015-06-28
CVE-2015-1959 [MEDIUM] CWE-284 CVE-2015-1959: IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.
nvd
CVE-2008-7289P4MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7289 [MEDIUM] CWE-20 CVE-2008-7289: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the si IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.
nvd
CVE-2014-6100P4LOWCVSS 3.5v6.1.0v6.1.0.0+73 more2014-10-19
CVE-2014-6100 [LOW] CWE-79 CVE-2014-6100: Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6 Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before 6.2.0.39-ISS-ITDS-FP0039, and 6.3 before 6.3.0.33-ISS-ITDS-IF0033, and IBM Security Directory Server 6.3.1 before 6.3.1.7-ISS-ISDS-IF0007, allows remote authenticated users to inject arbitrary web script or HTML via a cra
nvd
CVE-2010-4785P4MEDIUMCVSS 4.0v6.0v6.0.0.0+18 more2011-04-21
CVE-2010-4785 [MEDIUM] CWE-399 CVE-2010-4785: The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the NULL operation OID.
nvd
CVE-2010-4788P4MEDIUMCVSS 4.0v6.0v6.0.0.0+18 more2011-04-21
CVE-2010-4788 [MEDIUM] CWE-20 CVE-2010-4788: IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform certain locking of linked-list access, which allows remote authenticated users to cause a denial of service (daemon crash) via a paged search.
nvd
CVE-2010-4789P4MEDIUMCVSS 4.0v6.0v6.0.0.0+22 more2011-04-21
CVE-2010-4789 [MEDIUM] CWE-399 CVE-2010-4789: Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.
nvd
CVE-2010-4786P4MEDIUMCVSS 4.0v6.0v6.0.0.0+19 more2011-04-21
CVE-2010-4786 [MEDIUM] CWE-399 CVE-2010-4786: IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote au IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an improper ibm-slapdIdleTimeOut configuration setting.
nvd
CVE-2008-7290P4MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7290 [MEDIUM] CWE-399 CVE-2008-7290: Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2 Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
nvd
CVE-2010-4787P4MEDIUMCVSS 4.0v6.0v6.0.0.0+19 more2011-04-21
CVE-2010-4787 [MEDIUM] CWE-399 CVE-2010-4787: IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote au IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.
nvd
CVE-2008-7287P4MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7287 [MEDIUM] CWE-399 CVE-2008-7287: Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivol Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
nvd
CVE-2009-5072P4MEDIUMCVSS 4.0v6.0v6.0.0.0+17 more2011-04-21
CVE-2009-5072 [MEDIUM] CWE-399 CVE-2009-5072: Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.
nvd
CVE-2009-5073P4MEDIUMCVSS 4.0v6.0v6.0.0.0+15 more2011-04-21
CVE-2009-5073 [MEDIUM] CWE-399 CVE-2009-5073: IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote au IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry.
nvd
CVE-2011-1821P4MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2011-1821 [MEDIUM] CWE-399 CVE-2011-1821: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authen IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.
nvd
CVE-2007-6743P4MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2007-6743 [MEDIUM] CWE-399 CVE-2007-6743: Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 al Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 allows remote authenticated users to cause a denial of service (ABEND) via search operations that trigger recursive filter_free calls.
nvd