Show filters
252 Total Results
Displaying 31-40 of 252
Sort by:
Attacker Value
Unknown
CVE-2022-37967
Disclosure Date: November 09, 2022 (last updated January 11, 2025)
Windows Kerberos Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2022-38023
Disclosure Date: November 09, 2022 (last updated January 11, 2025)
Netlogon RPC Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2022-37966
Disclosure Date: November 09, 2022 (last updated January 11, 2025)
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2022-32743
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
0
Attacker Value
Unknown
CVE-2022-1615
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
0
Attacker Value
Unknown
CVE-2022-0336
Disclosure Date: August 29, 2022 (last updated October 08, 2023)
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on that account, such as one added when a computer is joined to a domain. An attacker who has the ability to write to an account can exploit this to perform a denial-of-service attack by adding an SPN that matches an existing service. Additionally, an attacker who can intercept traffic can impersonate existing services, resulting in a loss of confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2022-32746
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
0
Attacker Value
Unknown
CVE-2022-32745
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.
0
Attacker Value
Unknown
CVE-2022-32742
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).
0
Attacker Value
Unknown
CVE-2022-2031
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
0