Show filters
252 Total Results
Displaying 191-200 of 252
Sort by:
Attacker Value
Unknown
CVE-2007-2838
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
The populate_conns function in src/populate_conns.c in GSAMBAD 0.1.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gsambadtmp temporary file.
0
Attacker Value
Unknown
CVE-2007-2447
Disclosure Date: May 14, 2007 (last updated October 04, 2023)
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the "username map script" smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.
0
Attacker Value
Unknown
CVE-2007-2446
Disclosure Date: May 14, 2007 (last updated October 04, 2023)
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
0
Attacker Value
Unknown
CVE-2007-2444
Disclosure Date: May 14, 2007 (last updated October 04, 2023)
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
0
Attacker Value
Unknown
CVE-2007-0454
Disclosure Date: February 06, 2007 (last updated October 04, 2023)
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.
0
Attacker Value
Unknown
CVE-2007-0453
Disclosure Date: February 06, 2007 (last updated October 04, 2023)
Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.
0
Attacker Value
Unknown
CVE-2007-0452
Disclosure Date: February 06, 2007 (last updated October 04, 2023)
smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.
0
Attacker Value
Unknown
CVE-2006-6624
Disclosure Date: December 18, 2006 (last updated October 04, 2023)
The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command.
0
Attacker Value
Unknown
CVE-2006-3403
Disclosure Date: July 12, 2006 (last updated October 04, 2023)
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
0
Attacker Value
Unknown
CVE-2006-1059
Disclosure Date: March 30, 2006 (last updated February 22, 2025)
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.
0