CVE-2016-4052
- EPSS 12.51%
- Veröffentlicht 25.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
CVE-2016-4051
- EPSS 4.91%
- Veröffentlicht 25.04.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
CVE-2016-2115
- EPSS 23.77%
- Veröffentlicht 25.04.2016 00:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.
CVE-2016-2114
- EPSS 9.09%
- Veröffentlicht 25.04.2016 00:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client...
CVE-2016-2112
- EPSS 18.44%
- Veröffentlicht 25.04.2016 00:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade att...
CVE-2016-2113
- EPSS 6.3%
- Veröffentlicht 25.04.2016 00:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certific...
CVE-2016-2111
- EPSS 3.5%
- Veröffentlicht 25.04.2016 00:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive sessi...
CVE-2016-2110
- EPSS 19.66%
- Veröffentlicht 25.04.2016 00:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove app...
CVE-2015-5370
- EPSS 24.04%
- Veröffentlicht 25.04.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consum...
CVE-2013-7449
- EPSS 0.15%
- Veröffentlicht 21.04.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via...