- EPSS 28.45%
- Veröffentlicht 21.02.2022 15:15:07
- Zuletzt bearbeitet 23.04.2025 19:15:51
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fru...
CVE-2016-2124
- EPSS 0.79%
- Veröffentlicht 18.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 02:47:52
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
CVE-2020-25717
- EPSS 0.2%
- Veröffentlicht 18.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:33
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
CVE-2016-7797
- EPSS 2.95%
- Veröffentlicht 24.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
CVE-2015-1867
- EPSS 0.71%
- Veröffentlicht 12.08.2015 14:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
CVE-2015-1848
- EPSS 1.21%
- Veröffentlicht 14.05.2015 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this iss...