CVE-2016-4053
- EPSS 26.2%
- Veröffentlicht 25.04.2016 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
CVE-2016-4052
- EPSS 32.23%
- Veröffentlicht 25.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
CVE-2016-4051
- EPSS 10.32%
- Veröffentlicht 25.04.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
CVE-2016-2115
- EPSS 25.2%
- Veröffentlicht 25.04.2016 00:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.
CVE-2016-2114
- EPSS 9.09%
- Veröffentlicht 25.04.2016 00:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client...
CVE-2016-2112
- EPSS 18.44%
- Veröffentlicht 25.04.2016 00:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade att...
CVE-2016-2113
- EPSS 6.3%
- Veröffentlicht 25.04.2016 00:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certific...
CVE-2016-2111
- EPSS 3.79%
- Veröffentlicht 25.04.2016 00:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive sessi...
CVE-2016-2110
- EPSS 20.93%
- Veröffentlicht 25.04.2016 00:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove app...
CVE-2015-5370
- EPSS 25.48%
- Veröffentlicht 25.04.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consum...