Search CVE reports


Toggle filters

101 – 110 of 193 results


CVE-2017-9461

Medium priority
Fixed

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
Show less packages

CVE-2017-7494

High priority
Fixed

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
Show less packages

CVE-2017-2619

Medium priority

Some fixes available 5 of 6

Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2126

Medium priority

Some fixes available 4 of 5

Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using...

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2125

Medium priority

Some fixes available 5 of 6

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to...

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2123

High priority

Some fixes available 4 of 5

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active...

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2119

Medium priority

Some fixes available 2 of 4

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers,...

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2118

Medium priority

Some fixes available 6 of 7

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade...

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages

CVE-2016-2115

Medium priority

Some fixes available 6 of 7

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying...

2 affected packages

samba4, samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba4
samba
Show less packages

CVE-2016-2114

Medium priority

Some fixes available 5 of 6

The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by...

2 affected packages

samba, samba4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba
samba4
Show less packages