Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2011-2724

Disclosure Date: September 06, 2011 (last updated November 08, 2023)
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0547.
0
Attacker Value
Unknown

CVE-2010-0547

Disclosure Date: February 04, 2010 (last updated October 04, 2023)
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
0
Attacker Value
Unknown

CVE-2004-1154

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2004-2546

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).
0
Attacker Value
Unknown

CVE-2004-0815

Disclosure Date: November 03, 2004 (last updated February 22, 2025)
The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which could allow remote attackers to bypass the specified share restrictions and read, write, or list arbitrary files via "/.////" style sequences in pathnames.
0
Attacker Value
Unknown

CVE-2002-2196

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
0