Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2015-0283 1 Redhat 2 Enterprise Linux, Slapi-nis 2025-04-12 N/A
The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request for a (1) group with a large number of members or (2) user that belongs to a large number of groups.
CVE-2021-3480 3 Fedoraproject, Redhat, Slapi-nis Project 4 Fedora, Enterprise Linux, Rhel Eus and 1 more 2024-11-21 7.5 High
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.