Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9640

Опубликовано: 15 окт. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

EPSS

Процентиль: 23%
0.00077
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-908
CWE-908

Связанные уязвимости

CVSS3: 4.3
ubuntu
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
redhat
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
debian
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where unin ...

CVSS3: 4.3
github
6 месяцев назад

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability.

CVSS3: 4.3
fstec
6 месяцев назад

Уязвимость модуля vfs_streams_xattr пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 23%
0.00077
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-908
CWE-908