Padl Software maintains a focused set of authentication and directory-integration tools, primarily PAM LDAP, NSS LDAP, and migration utilities, that enable Unix and Linux systems to authenticate against LDAP directories. These products occupy a durable niche in enterprise infrastructure, where they mediate the critical boundary between local system authentication and centralized directory services. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Padl Software over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0734HIGH Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restriction | Oct 20, 2003 | 10.0 | 25 | NO | NO |
CVE-2002-0825HIGH Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Aug 12, 2002 | 7.5 | 25 | NO | NO |
CVE-2002-0374HIGH Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configu | May 29, 2002 | 7.5 | 22 | NO | NO |
CVE-2005-2641HIGH Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also b | Aug 23, 2005 | 7.5 | 20 | NO | NO |
CVE-2002-0735HIGH Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of se | Aug 12, 2002 | 7.5 | 20 | NO | NO |
PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly | Feb 2, 2006 | 2.1 | 11 | NO | NO |
PADL MigrationTools 46, when a failure occurs, stores contents of /etc/shadow in a world-readable /tmp/nis.$$.ldif file, and possibly other sensitive information in other temporary | Dec 31, 2005 | 2.1 | 11 | NO | NO |
nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests. | Dec 11, 2000 | 1.2 | 10 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Padl Software.
Media articles that mention a CVE ID that affects a product developed by Padl Software — matched by CVE ID, not by vendor name.