Show filters
252 Total Results
Displaying 181-190 of 252
Sort by:
Attacker Value
Unknown

CVE-2009-0022

Disclosure Date: January 05, 2009 (last updated October 04, 2023)
Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.
0
Attacker Value
Unknown

CVE-2008-4314

Disclosure Date: December 01, 2008 (last updated October 04, 2023)
smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.
0
Attacker Value
Unknown

CVE-2008-3789

Disclosure Date: August 27, 2008 (last updated October 04, 2023)
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.
0
Attacker Value
Unknown

CVE-2008-1105

Disclosure Date: May 29, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.
0
Attacker Value
Unknown

CVE-2008-1720

Disclosure Date: April 10, 2008 (last updated October 04, 2023)
Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2007-6015

Disclosure Date: December 13, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.
0
Attacker Value
Unknown

CVE-2007-4572

Disclosure Date: November 16, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.
0
Attacker Value
Unknown

CVE-2007-5398

Disclosure Date: November 16, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.
0
Attacker Value
Unknown

CVE-2007-4138

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc2307 or sfu, grants all local users the privileges of gid 0 when the (1) RFC2307 or (2) Services for UNIX (SFU) primary group attribute is not defined.
0
Attacker Value
Unknown

CVE-2007-2407

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
The Samba server on Apple Mac OS X 10.3.9 and 10.4.10, when Windows file sharing is enabled, does not enforce disk quotas after dropping privileges, which allows remote authenticated users to use disk space in excess of quota.
0