Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2004-0882

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
0
Attacker Value
Unknown

CVE-2004-0930

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
0
Attacker Value
Unknown

CVE-2004-1154

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2004-0808

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.
0
Attacker Value
Unknown

CVE-2004-2546

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).
0
Attacker Value
Unknown

CVE-2004-0815

Disclosure Date: November 03, 2004 (last updated February 22, 2025)
The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
0
Attacker Value
Unknown

CVE-2004-0807

Disclosure Date: September 13, 2004 (last updated February 22, 2025)
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
0
Attacker Value
Unknown

CVE-2004-0186

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.
0
Attacker Value
Unknown

CVE-2004-0082

Disclosure Date: March 03, 2004 (last updated February 22, 2025)
The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.
0