Netscape Directory Server vulnerabilities

6 known vulnerabilities affecting netscape/directory_server.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2004-1236CRITICALCVSS 10.0v3.62004-12-31
CVE-2004-1236 [CRITICAL] CVE-2004-1236: Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other ope Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.
nvd
CVE-2004-0826HIGHCVSS 7.5v1.3v3.1+4 more2004-12-31
CVE-2004-0826 [HIGH] CVE-2004-0826: Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attacke Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
nvd
CVE-2001-0164HIGHCVSS 7.5≤ 4.122001-06-02
CVE-2001-0164 [HIGH] CVE-2001-0164: Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a den Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.
nvd
CVE-2000-1076CRITICALCVSS 10.0v4.122000-12-11
CVE-2000-1076 [CRITICAL] CVE-2000-1076: Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administra Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.
nvd
CVE-2000-1075MEDIUMCVSS 5.0PoCv4.122000-12-11
CVE-2000-1075 [MEDIUM] CVE-2000-1075: Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.
nvd
CVE-1999-0007MEDIUMCVSS 5.0v1.3v3.1+1 more1998-06-26
CVE-1999-0007 [MEDIUM] CWE-327 CVE-1999-0007: Information from SSL-encrypted sessions via PKCS #1. Information from SSL-encrypted sessions via PKCS #1.
nvd