Samba

Samba

211 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.67%
  • Published 10.12.2013 06:14:55
  • Last modified 11.04.2025 00:51:21

Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via...

Exploit
  • EPSS 0.15%
  • Published 03.12.2013 19:55:03
  • Last modified 11.04.2025 00:51:21

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended a...

  • EPSS 1.31%
  • Published 13.11.2013 15:55:03
  • Last modified 11.04.2025 00:51:21

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file an...

  • EPSS 0.23%
  • Published 13.11.2013 15:55:03
  • Last modified 11.04.2025 00:51:21

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access t...

  • EPSS 86.81%
  • Published 06.08.2013 02:56:00
  • Last modified 11.04.2025 00:51:21

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

  • EPSS 1.88%
  • Published 26.03.2013 21:55:01
  • Last modified 11.04.2025 00:51:21

The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated u...

  • EPSS 0.28%
  • Published 19.03.2013 17:55:02
  • Last modified 11.04.2025 00:51:21

Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard file...

  • EPSS 4.07%
  • Published 02.02.2013 20:55:03
  • Last modified 11.04.2025 00:51:21

The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.

  • EPSS 1.92%
  • Published 02.02.2013 20:55:03
  • Last modified 11.04.2025 00:51:21

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging kn...

  • EPSS 0.21%
  • Published 17.01.2013 21:55:00
  • Last modified 11.04.2025 00:51:21

Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on mo...