RSS   Vulnerabilities for 'Nss ldap'   RSS

2005-06-30
 
CVE-2005-2069

 

 
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

 
2002-08-12
 
CVE-2002-0825

 

 
Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

 
 
CVE-2002-0735

 

 
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.

 
2000-12-11
 
CVE-2000-1045

 

 
nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.

 

 >>> Vendor: Padl software 3 Products
Nss ldap
Pam ldap
Migrationtools


Copyright 2024, cxsecurity.com

 

Back to Top