Vulnerabilities > IBM > Tivoli Directory Server > 5.2.0.4

DATE CVE VULNERABILITY TITLE RISK
2011-04-21 CVE-2011-1822 Credentials Management vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.
local
low complexity
ibm CWE-255
2.1
2011-04-21 CVE-2011-1821 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.
network
low complexity
ibm microsoft CWE-399
4.0
2011-04-21 CVE-2011-1820 Information Exposure vulnerability in IBM Tivoli Directory Server
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.
local
low complexity
ibm CWE-200
1.7
2011-04-21 CVE-2011-1206 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Tivoli Directory Server
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request.
network
low complexity
ibm CWE-119
critical
10.0
2011-04-21 CVE-2008-7290 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2008-7289 Improper Input Validation vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.
network
low complexity
ibm CWE-20
4.0
2011-04-21 CVE-2008-7288 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
network
low complexity
ibm CWE-399
5.0
2011-04-21 CVE-2008-7287 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2007-6743 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 allows remote authenticated users to cause a denial of service (ABEND) via search operations that trigger recursive filter_free calls.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2007-6742 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.
network
low complexity
ibm CWE-399
6.8