Vulnerabilities > IBM > Tivoli Directory Server

DATE CVE VULNERABILITY TITLE RISK
2011-04-21 CVE-2008-7289 Improper Input Validation vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.
network
low complexity
ibm CWE-20
4.0
2011-04-21 CVE-2008-7288 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
network
low complexity
ibm CWE-399
5.0
2011-04-21 CVE-2008-7287 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2007-6743 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 allows remote authenticated users to cause a denial of service (ABEND) via search operations that trigger recursive filter_free calls.
network
low complexity
ibm CWE-399
4.0
2011-04-21 CVE-2007-6742 Resource Management Errors vulnerability in IBM Tivoli Directory Server 5.2.0/5.2.0.4
The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.
network
low complexity
ibm CWE-399
6.8
2010-11-09 CVE-2010-4217 Resource Management Errors vulnerability in IBM Tivoli Directory Server
Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.
network
low complexity
ibm CWE-399
5.0
2010-11-09 CVE-2010-4216 Buffer Errors vulnerability in IBM Tivoli Directory Server 6.0/6.0.0.7/6.0.0.8
IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.
network
low complexity
ibm CWE-119
5.0
2010-08-02 CVE-2010-2927 Improper Authentication vulnerability in IBM Tivoli Directory Server
The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.
network
low complexity
ibm CWE-287
5.0
2010-01-14 CVE-2010-0312 Improper Input Validation vulnerability in IBM Tivoli Directory Server 6.2
The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).
network
low complexity
ibm linux CWE-20
5.0
2009-09-08 CVE-2009-3090 Denial-Of-Service vulnerability in IBM Tivoli Directory Server 6.0
Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
network
low complexity
ibm linux
5.0