Show filters
60 Total Results
Displaying 51-60 of 60
Sort by:
Attacker Value
Unknown

CVE-2004-1880

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).
0
Attacker Value
Unknown

CVE-2004-0823

Disclosure Date: September 07, 2004 (last updated February 22, 2025)
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
0
Attacker Value
Unknown

CVE-2003-1201

Disclosure Date: March 20, 2003 (last updated February 22, 2025)
ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).
0
Attacker Value
Unknown

CVE-2002-1508

Disclosure Date: February 19, 2003 (last updated February 22, 2025)
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.
0
Attacker Value
Unknown

CVE-2002-1379

Disclosure Date: January 02, 2003 (last updated February 22, 2025)
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.
0
Attacker Value
Unknown

CVE-2002-1378

Disclosure Date: January 02, 2003 (last updated February 22, 2025)
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in libldap, (4) a certain access control list that causes an overflow in slapd, or (5) a long generated filename for logging rejected replication requests.
0
Attacker Value
Unknown

CVE-2002-0045

Disclosure Date: January 31, 2002 (last updated February 22, 2025)
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.
0
Attacker Value
Unknown

CVE-2001-0977

Disclosure Date: July 16, 2001 (last updated February 22, 2025)
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
0
Attacker Value
Unknown

CVE-2000-0748

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.
0
Attacker Value
Unknown

CVE-2000-0336

Disclosure Date: April 21, 2000 (last updated February 22, 2025)
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
0