2024

2023

2022

2021

2020

2019

CVE-2019-14824 (v3: 6.5) 8 Nov 2019
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

2018

2017

CVE-2017-5357 (v3: 7.5) 17 Feb 2017
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.

2016

2015

CVE-2015-5221 (v3: 5.5) 25 Jul 2017
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.