CVE-2020-10704
- EPSS 8.93%
- Veröffentlicht 06.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:53
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of ser...
CVE-2020-10700
- EPSS 2.86%
- Veröffentlicht 04.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:52
A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versi...
CVE-2019-14902
- EPSS 2.71%
- Veröffentlicht 21.01.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:39
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on a...
CVE-2019-14907
- EPSS 8.97%
- Veröffentlicht 21.01.2020 18:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such st...
CVE-2019-19344
- EPSS 2.31%
- Veröffentlicht 21.01.2020 18:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the ori...
CVE-2011-3585
- EPSS 0.55%
- Veröffentlicht 31.12.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 01:30:48
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.
CVE-2019-14861
- EPSS 1.65%
- Veröffentlicht 10.12.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:31
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stor...
CVE-2019-14870
- EPSS 4.67%
- Veröffentlicht 10.12.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:33
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in an...
CVE-2019-10218
- EPSS 6.75%
- Veröffentlicht 06.11.2019 10:15:10
- Zuletzt bearbeitet 21.11.2024 04:18:40
A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB...
CVE-2019-14833
- EPSS 1.27%
- Veröffentlicht 06.11.2019 10:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:27
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be config...