Unspecified 389-Ds-Base vulnerabilities
2 known vulnerabilities affecting unspecified/389-ds-base.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2018-1089HIGHCVSS 7.5v389-ds-base 1.4.0.9v389-ds-base 1.3.8.1+1 more2018-05-09
CVE-2018-1089 [HIGH] CWE-122 CVE-2018-1089: 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters w
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
cvelistv5nvd
CVE-2017-2591HIGHCVSS 7.5v389-ds-base 1.3.62018-04-30
CVE-2017-2591 [LOW] CWE-122 CVE-2017-2591: 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniquen
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP serv
cvelistv5nvd