Show filters
183 Total Results
Displaying 31-40 of 183
Sort by:
Attacker Value
Unknown

CVE-2019-10224

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
Attacker Value
Unknown

CVE-2019-14824

Disclosure Date: November 08, 2019 (last updated November 27, 2024)
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Attacker Value
Unknown

CVE-2010-2222

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
Attacker Value
Unknown

CVE-2019-4538

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 165660.
Attacker Value
Unknown

CVE-2019-4549

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.
Attacker Value
Unknown

CVE-2019-4520

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.
Attacker Value
Unknown

CVE-2019-4539

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.
Attacker Value
Unknown

CVE-2019-4542

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.
Attacker Value
Unknown

CVE-2019-19344

Disclosure Date: August 07, 2019 (last updated February 21, 2025)
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the original buffer.
Attacker Value
Unknown

CVE-2019-10171

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.