Search CVE reports


Toggle filters

11 – 20 of 193 results


CVE-2023-34968

Medium priority

Some fixes available 9 of 12

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-34967

Medium priority
Fixed

A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Not affected
Show less packages

CVE-2023-34966

Medium priority
Fixed

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-3347

Medium priority
Fixed

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2022-2127

Medium priority

Some fixes available 9 of 12

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-0922

Medium priority

Some fixes available 9 of 12

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2023-0614

Medium priority

Some fixes available 11 of 17

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

2 affected packages

ldb, samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldb Not in release Fixed Fixed Vulnerable
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2023-0225

Medium priority
Fixed

A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2018-14628

Low priority

Some fixes available 4 of 12

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-3592

Medium priority
Not affected

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages