Vulnerabilities > Redhat > Freeipa > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-11-03 CVE-2013-0336 Improper Input Validation vulnerability in Redhat Freeipa
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.
network
low complexity
redhat CWE-20
5.0
2014-05-29 CVE-2013-0199 Permissions, Privileges, and Access Controls vulnerability in Redhat Freeipa
The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.
network
low complexity
redhat CWE-264
5.0