{"api_version":"1","generated_at":"2026-07-23T06:56:03+00:00","cve":"CVE-2007-4566","urls":{"html":"https://cve.report/CVE-2007-4566","api":"https://cve.report/api/cve/CVE-2007-4566.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4566","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4566"},"summary":{"title":"CVE-2007-4566","description":"Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-28 01:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/25460","name":"http://www.securityfocus.com/bid/25460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SIDVault 'simple_bind()' Function Multiple Remote Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2976","name":"http://www.vupen.com/english/advisories/2007/2976","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36272","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018612","name":"http://www.securitytracker.com/id?1018612","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SIDVault Login Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3061","name":"http://securityreason.com/securityalert/3061","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SIDVault LDAP Server Remote Buffer Overflow - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065453.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065453.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-disclosure] SIDVault LDAP Server Remote Buffer Overflow","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/26613","name":"http://secunia.com/advisories/26613","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SIDVault LDAP Buffer Overflow Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/477821/100/0/threaded","name":"http://www.securityfocus.com/archive/1/477821/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4566","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4566","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4566","vulnerable":"1","versionEndIncluding":"2.0e","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alpha_centauri_software","cpe5":"sidvault_ldap_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.794Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1018612","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018612"},{"name":"26613","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26613"},{"name":"3061","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3061"},{"name":"25460","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25460"},{"name":"20070826 SIDVault LDAP Server Remote Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/477821/100/0/threaded"},{"name":"sidvault-ldap-bo(36272)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36272"},{"name":"20070826 SIDVault LDAP Server Remote Buffer Overflow","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065453.html"},{"name":"ADV-2007-2976","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2976"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1018612","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018612"},{"name":"26613","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26613"},{"name":"3061","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3061"},{"name":"25460","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25460"},{"name":"20070826 SIDVault LDAP Server Remote Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/477821/100/0/threaded"},{"name":"sidvault-ldap-bo(36272)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36272"},{"name":"20070826 SIDVault LDAP Server Remote Buffer Overflow","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065453.html"},{"name":"ADV-2007-2976","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2976"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4566","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1018612","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018612"},{"name":"26613","refsource":"SECUNIA","url":"http://secunia.com/advisories/26613"},{"name":"3061","refsource":"SREASON","url":"http://securityreason.com/securityalert/3061"},{"name":"25460","refsource":"BID","url":"http://www.securityfocus.com/bid/25460"},{"name":"20070826 SIDVault LDAP Server Remote Buffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/477821/100/0/threaded"},{"name":"sidvault-ldap-bo(36272)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36272"},{"name":"20070826 SIDVault LDAP Server Remote Buffer Overflow","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065453.html"},{"name":"ADV-2007-2976","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2976"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4566","datePublished":"2007-08-28T01:00:00.000Z","dateReserved":"2007-08-27T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.794Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-28 01:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:alpha_centauri_software:sidvault_ldap_server:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0e","matchCriteriaId":"A456360A-BAD4-4C76-B9CB-2FF4EBB12A5C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4566","Ordinal":"1","Title":"CVE-2007-4566","CVE":"CVE-2007-4566","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4566","Ordinal":"1","NoteData":"Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.","Type":"Description","Title":"CVE-2007-4566"},{"CveYear":"2007","CveId":"4566","Ordinal":"2","NoteData":"2007-08-27","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4566","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}