Vulnerability Database

314,343

Total vulnerabilities in the database

CVE-2005-3170

The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.

  • Published: Oct 6, 2005
  • Updated: Nov 9, 2025
  • CVE: CVE-2005-3170
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

CVSS v2:

  • Severity: Medium
  • Score: 5.1
  • AV:N/AC:H/Au:N/C:P/I:P/A:P