19 results (0.012 seconds)

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP search request. Múltiples vulnerabilidades sin especificar en (1) ns-slapd y (2) slapd.exe en Sun Directory Server Enterprise Edition v7.0, Sun Java System Directory Server v5.2, y Sun Java System Directory Server Enterprise Edition v6.0 a la v6.3.1, permite a atacantes remotos provocar una denegación de servicio (caída de demonio) a través de una petición de búsqueda manipulada en el LDAP. • http://sunsolve.sun.com/search/document.do?assetkey=1-21-143884-01-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-275711-1 http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021788.1-1 https://exchange.xforce.ibmcloud.com/vulnerabilities/56603 •

CVSS: 5.0EPSS: 4%CPEs: 1EXPL: 3

The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message. La función core_get_proxyauth_dn en ns-slapd en Sun Java System Directory Server Enterprise Edition v7.0, permite a atacantes remotos provocar una denegación de servicio (deferencia a puntero NULL y caída de demonio) a través de un mensaje LDAP Search Request manipulado. • https://www.exploit-db.com/exploits/33483 http://intevydis.blogspot.com/2010/01/sun-directory-server-70.html http://secunia.com/advisories/37978 http://securitytracker.com/id?1023431 http://www.securityfocus.com/bid/37699 http://www.vupen.com/english/advisories/2010/0085 https://exchange.xforce.ibmcloud.com/vulnerabilities/55511 •

CVSS: 5.0EPSS: 1%CPEs: 5EXPL: 0

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no operations on these connections, aka Bug Id 6648665. Directory Proxy Server (DPS) en Sun Java System Directory Server Enterprise Edition v6.0 hasta v6.3.1 no implementa adecuadamente los valores de configuración para el máximo número de conexiones clientes, permitiendo a atacantes remotos provocar una denegación de servicio (agotamiento del slot de conexión) al realizar múltiples conexiones y no realizando operaciones en estas conexiones, también conocido como Bug Id 6648665. • http://secunia.com/advisories/37915 http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1 http://www.securityfocus.com/bid/37481 http://www.securitytracker.com/id?1023389 http://www.vupen.com/english/advisories/2009/3647 • CWE-16: Configuration •

CVSS: 5.0EPSS: 1%CPEs: 5EXPL: 0

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not enable the SO_KEEPALIVE socket option, which makes it easier for remote attackers to cause a denial of service (connection slot exhaustion) via multiple connections, aka Bug Id 6782659. Directory Proxy Server (DPS) en Sun Java System Directory Server Enterprise Edition v6.0 hasta v6.3.1 no habilita opción SO_KEEPALIVE socket, facilitando a atacantes remotos provocar una denegación de servicio (agotamiento del slot de conexión) mediante múltiples conexiones, también conocido como Bug Id 6782659. • http://secunia.com/advisories/37915 http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1 http://www.securityfocus.com/bid/37481 http://www.securitytracker.com/id?1023389 http://www.vupen.com/english/advisories/2009/3647 •

CVSS: 6.8EPSS: 1%CPEs: 4EXPL: 0

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593. Directory Proxy Server (DPS) en Sun Java System Directory Server Enterprise Edition v6.0 hasta v6.3.1 no maneja adecuadamente múltiples conexiones de cliente en un periodo corto de tiempo, permitiendo a atacantes remotos secuestrar la conexión interna de un usuario autenticado, al realizar una conexión cliente en las circunstancias oportunas, relacionado con "long binds", también conocido como Bug Ids 6828462 y 6823593. • http://secunia.com/advisories/37915 http://sunsolve.sun.com/search/document.do?assetkey=1-21-141958-01-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-270789-1 http://www.securityfocus.com/bid/37481 http://www.securitytracker.com/id?1023389 http://www.vupen.com/english/advisories/2009/3647 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •