RSS   Vulnerabilities for 'Directory server'   RSS

2008-08-29
 
CVE-2008-3283

CWE-399
 

 
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.

 
 
CVE-2008-2930

CWE-399
 

 
Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.

 
 
CVE-2008-2929

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.

 

 >>> Vendor: Fedora 3 Products
Directory server
Newsx
Pacemaker configuration system


Copyright 2024, cxsecurity.com

 

Back to Top