Samba

Samba

212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.53%
  • Veröffentlicht 22.08.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:16

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between ...

  • EPSS 17.35%
  • Veröffentlicht 22.08.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:16

A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause a denial of service against a samba server, used as a Active Directory Domain Controller. All version...

  • EPSS 8.03%
  • Veröffentlicht 27.07.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 03:08:56

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attac...

  • EPSS 19.45%
  • Veröffentlicht 26.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:08:56

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in pl...

  • EPSS 58.95%
  • Veröffentlicht 26.07.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:08:57

An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to ...

  • EPSS 27.18%
  • Veröffentlicht 13.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:04

All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls c...

  • EPSS 5.07%
  • Veröffentlicht 13.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:05

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privi...

Exploit
  • EPSS 18.12%
  • Veröffentlicht 12.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:50

Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.

  • EPSS 39.46%
  • Veröffentlicht 27.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

  • EPSS 43.43%
  • Veröffentlicht 27.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.