Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2011-2724

Disclosure Date: September 06, 2011 (last updated November 08, 2023)
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
0
Attacker Value
Unknown

CVE-2007-6015

Disclosure Date: December 13, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.
0
Attacker Value
Unknown

CVE-2004-1154

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2004-0829

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.
0
Attacker Value
Unknown

CVE-2003-0201

Disclosure Date: May 05, 2003 (last updated February 22, 2025)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2003-0196

Disclosure Date: May 05, 2003 (last updated February 22, 2025)
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
0
Attacker Value
Unknown

CVE-2003-0086

Disclosure Date: March 31, 2003 (last updated February 22, 2025)
The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.
0
Attacker Value
Unknown

CVE-2003-0085

Disclosure Date: March 31, 2003 (last updated February 22, 2025)
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2001-1162

Disclosure Date: June 23, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.
0
Attacker Value
Unknown

CVE-2000-0936

Disclosure Date: December 19, 2000 (last updated February 22, 2025)
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.
0