Show filters
252 Total Results
Displaying 211-220 of 252
Sort by:
Attacker Value
Unknown
CVE-2004-2565
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.
0
Attacker Value
Unknown
CVE-2004-0815
Disclosure Date: November 03, 2004 (last updated February 22, 2025)
The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
0
Attacker Value
Unknown
CVE-2004-0807
Disclosure Date: September 13, 2004 (last updated February 22, 2025)
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
0
Attacker Value
Unknown
CVE-2004-0686
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2004-0600
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.
0
Attacker Value
Unknown
CVE-2004-0186
Disclosure Date: March 15, 2004 (last updated February 22, 2025)
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.
0
Attacker Value
Unknown
CVE-2004-0082
Disclosure Date: March 03, 2004 (last updated February 22, 2025)
The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.
0
Attacker Value
Unknown
CVE-2004-2086
Disclosure Date: February 06, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.
0
Attacker Value
Unknown
CVE-2004-0028
Disclosure Date: February 03, 2004 (last updated February 22, 2025)
jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2003-1287
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.
0