Show filters
252 Total Results
Displaying 151-160 of 252
Sort by:
Attacker Value
Unknown
CVE-2013-4124
Disclosure Date: August 06, 2013 (last updated October 05, 2023)
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
0
Attacker Value
Unknown
CVE-2013-0454
Disclosure Date: March 26, 2013 (last updated October 05, 2023)
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
0
Attacker Value
Unknown
CVE-2013-1863
Disclosure Date: March 19, 2013 (last updated October 05, 2023)
Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard filesystem operations.
0
Attacker Value
Unknown
CVE-2013-0213
Disclosure Date: February 02, 2013 (last updated October 05, 2023)
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
0
Attacker Value
Unknown
CVE-2013-0214
Disclosure Date: February 02, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
0
Attacker Value
Unknown
CVE-2013-0172
Disclosure Date: January 17, 2013 (last updated October 05, 2023)
Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects by leveraging (1) objectClass access by a user, (2) objectClass access by a group, or (3) write access to an attribute.
0
Attacker Value
Unknown
CVE-2012-2111
Disclosure Date: April 30, 2012 (last updated October 04, 2023)
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.
0
Attacker Value
Unknown
CVE-2012-1182 — Samba RCE via RPC
Disclosure Date: April 10, 2012 (last updated November 24, 2024)
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.
0
Attacker Value
Unknown
CVE-2012-0870
Disclosure Date: February 23, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a Batched (aka AndX) request that triggers infinite recursion.
0
Attacker Value
Unknown
CVE-2012-0817
Disclosure Date: January 30, 2012 (last updated October 04, 2023)
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
0