CVE-2012-2111
- EPSS 1.38%
- Veröffentlicht 30.04.2012 14:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges da...
- EPSS 78.17%
- Veröffentlicht 10.04.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execut...
CVE-2012-0870
- EPSS 48.9%
- Veröffentlicht 23.02.2012 12:33:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly ...
- EPSS 2.86%
- Veröffentlicht 30.01.2012 17:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
- EPSS 0.41%
- Veröffentlicht 02.10.2011 20:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.
CVE-2011-2724
- EPSS 0.44%
- Veröffentlicht 06.09.2011 16:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denia...
CVE-2011-2522
- EPSS 11.36%
- Veröffentlicht 29.07.2011 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start...
CVE-2011-2694
- EPSS 2.5%
- Veröffentlicht 29.07.2011 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the usernam...
CVE-2011-1678
- EPSS 0.28%
- Veröffentlicht 10.04.2011 02:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigge...
- EPSS 18.03%
- Veröffentlicht 01.03.2011 23:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite ...