Redhat Directory Server vulnerabilities
26 known vulnerabilities affecting redhat/directory_server.
Total CVEs
26
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM12LOW5
Vulnerabilities
Page 2 of 2
CVE-2008-2929MEDIUMCVSS 4.3v7.1v8.02008-08-29
CVE-2008-2929 [MEDIUM] CWE-79 CVE-2008-2929: Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server
Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use %
nvd
CVE-2008-1677HIGHCVSS 7.5v7.1v8.02008-05-12
CVE-2008-1677 [HIGH] CWE-120 CVE-2008-1677: Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6
Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LDAP query that triggers the overflow during translation to a regular expression.
nvd
CVE-2008-0892CRITICALCVSS 9.0v7.1v82008-04-16
CVE-2008-0892 [CRITICAL] CWE-20 CVE-2008-0892: The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used b
The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands.
nvd
CVE-2008-0893HIGHCVSS 7.5v8.02008-04-16
CVE-2008-0893 [HIGH] CWE-264 CVE-2008-0893: Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properl
Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions.
nvd
CVE-2008-0889LOWCVSS 2.1v8.02008-03-20
CVE-2008-0889 [LOW] CWE-264 CVE-2008-0889: Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions fo
Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions for the redhat-idm-console script, which allows local users to execute arbitrary code by modifying the script.
nvd
CVE-2008-0890MEDIUMCVSS 4.6≤ 7.12008-03-12
CVE-2008-0890 [MEDIUM] CWE-264 CVE-2008-0890: Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which all
Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors.
nvd
← Previous2 / 2