Samba

Samba

211 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.56%
  • Veröffentlicht 06.11.2019 10:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:29

A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

  • EPSS 4.79%
  • Veröffentlicht 03.09.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:38

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared ...

  • EPSS 2.41%
  • Veröffentlicht 31.07.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 03:53:28

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept th...

  • EPSS 6.37%
  • Veröffentlicht 19.06.2019 12:15:10
  • Zuletzt bearbeitet 21.11.2024 04:22:50

Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.

  • EPSS 4.37%
  • Veröffentlicht 19.06.2019 12:15:10
  • Zuletzt bearbeitet 21.11.2024 04:22:50

Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.

Exploit
  • EPSS 0.68%
  • Veröffentlicht 09.04.2019 16:29:01
  • Zuletzt bearbeitet 14.01.2025 19:29:55

A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700,...

  • EPSS 2.86%
  • Veröffentlicht 09.04.2019 16:29:01
  • Zuletzt bearbeitet 21.11.2024 04:42:47

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation...

  • EPSS 9.73%
  • Veröffentlicht 06.03.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:42:37

A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of ...

Exploit
  • EPSS 14.07%
  • Veröffentlicht 28.11.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:27

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denia...

  • EPSS 9.75%
  • Veröffentlicht 28.11.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:25

Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validl...