peter bassill · operator
$ cve CVE-2007-4566 JSON

CVE-2007-4566 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 15.3% (pctl 97)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS15.33% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-08-28
Last modified2026-06-16

Affected (1)

VendorProduct
alpha centauri softwaresidvault ldap server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD