Vulnerabilities > Fedoraproject > 389 Directory Server > 1.3.6.7

DATE CVE VULNERABILITY TITLE RISK
2018-01-24 CVE-2017-15135 Unspecified vulnerability in Fedoraproject 389 Directory Server
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process.
network
high complexity
fedoraproject
8.1
2017-08-16 CVE-2017-7551 Unspecified vulnerability in Fedoraproject 389 Directory Server 1.3.5.19/1.3.6.7
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
network
low complexity
fedoraproject
critical
9.8