- EPSS 28.45%
- Veröffentlicht 21.02.2022 15:15:07
- Zuletzt bearbeitet 23.04.2025 19:15:51
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fru...
CVE-2021-4091
- EPSS 0.18%
- Veröffentlicht 18.02.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:36:53
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
CVE-2016-2124
- EPSS 0.79%
- Veröffentlicht 18.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 02:47:52
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
CVE-2020-25717
- EPSS 0.2%
- Veröffentlicht 18.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:33
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
- EPSS 0.28%
- Veröffentlicht 18.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:18:34
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and a...
CVE-2021-4034
- EPSS 86.52%
- Veröffentlicht 28.01.2022 20:15:12
- Zuletzt bearbeitet 03.04.2025 18:53:12
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
CVE-2021-3622
- EPSS 0.58%
- Veröffentlicht 23.12.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:00
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat f...
CVE-2021-3672
- EPSS 0.11%
- Veröffentlicht 23.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:07
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulner...
- EPSS 94.43%
- Veröffentlicht 16.09.2021 15:15:07
- Zuletzt bearbeitet 16.05.2025 15:27:13
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-20233
- EPSS 0.14%
- Veröffentlicht 03.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:10
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters...