Show filters
252 Total Results
Displaying 61-70 of 252
Sort by:
Attacker Value
Unknown
CVE-2021-20208
Disclosure Date: April 19, 2021 (last updated February 22, 2025)
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2021-27185
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
0
Attacker Value
Unknown
CVE-2020-14318
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
0
Attacker Value
Unknown
CVE-2020-14383
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.
0
Attacker Value
Unknown
CVE-2020-14323
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
0
Attacker Value
Unknown
CVE-2020-14342
Disclosure Date: September 09, 2020 (last updated February 22, 2025)
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.
0
Attacker Value
Unknown
CVE-2020-10730
Disclosure Date: July 07, 2020 (last updated February 21, 2025)
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. This flaw allows an authenticated user to possibly trigger a use-after-free or NULL pointer dereference. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-10745
Disclosure Date: July 07, 2020 (last updated February 21, 2025)
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2020-10760
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
0
Attacker Value
Unknown
CVE-2020-14303
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
0