Slapi-Nis Project Slapi-Nis vulnerabilities
2 known vulnerabilities affecting slapi-nis_project/slapi-nis.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2021-3480HIGHCVSS 7.5fixed in 0.56.7vslapi-nis 0.56.72021-05-20
CVE-2021-3480 [HIGH] CWE-476 CVE-2021-3480: A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsi
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
nvdosv
CVE-2015-0283HIGHCVSS 7.8≥ 0, < 0.54.2-12015-03-30
CVE-2015-0283 [HIGH] CVE-2015-0283: The slapi-nis plug-in before 0
The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request for a (1) group with a large number of members or (2) user that belongs to a large number of groups.
osv