CVE-2013-4408
- EPSS 2.67%
- Veröffentlicht 10.12.2013 06:14:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via...
CVE-2012-6150
- EPSS 0.15%
- Veröffentlicht 03.12.2013 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended a...
- EPSS 1.31%
- Veröffentlicht 13.11.2013 15:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file an...
CVE-2013-4476
- EPSS 0.23%
- Veröffentlicht 13.11.2013 15:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access t...
- EPSS 86.81%
- Veröffentlicht 06.08.2013 02:56:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
- EPSS 1.88%
- Veröffentlicht 26.03.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated u...
- EPSS 0.28%
- Veröffentlicht 19.03.2013 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard file...
CVE-2013-0213
- EPSS 4.07%
- Veröffentlicht 02.02.2013 20:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
CVE-2013-0214
- EPSS 1.92%
- Veröffentlicht 02.02.2013 20:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging kn...
CVE-2013-0172
- EPSS 0.21%
- Veröffentlicht 17.01.2013 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on mo...