Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17

Количество 17

fstec логотип

BDU:2026-07316

2 месяца назад

Уязвимость функции check password script модуля DCE/RPC SAMR server пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2026-4408

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
EPSS: Низкий
redhat логотип

CVE-2026-4408

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2026-4408

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
EPSS: Низкий
debian логотип

CVE-2026-4408

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfigur ...

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-jg8v-92xc-cx65

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
EPSS: Низкий
oracle-oval логотип

ELSA-2026-22644

около 2 месяцев назад

ELSA-2026-22644: samba security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2108-1

2 месяца назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2073-1

2 месяца назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2074-1

2 месяца назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2072-1

2 месяца назад

Security update for samba

EPSS: Низкий
rocky логотип

RLSA-2026:22644

около 2 месяцев назад

Important: samba security update

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20905-1

около 2 месяцев назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2076-1

2 месяца назад

Security update for samba

EPSS: Низкий
rocky логотип

RLSA-2026:25049

около 2 месяцев назад

Critical: samba security update

EPSS: Низкий
rocky логотип

RLSA-2026:22963

около 2 месяцев назад

Critical: samba security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-25049

около 1 месяца назад

ELSA-2026-25049: samba security update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-07316

Уязвимость функции check password script модуля DCE/RPC SAMR server пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
3%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
3%
Низкий
2 месяца назад
redhat логотип
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
3%
Низкий
2 месяца назад
nvd логотип
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
3%
Низкий
2 месяца назад
debian логотип
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfigur ...

CVSS3: 9
3%
Низкий
2 месяца назад
github логотип
GHSA-jg8v-92xc-cx65

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
3%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-22644

ELSA-2026-22644: samba security update (IMPORTANT)

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2108-1

Security update for samba

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2073-1

Security update for samba

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2074-1

Security update for samba

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2072-1

Security update for samba

2 месяца назад
rocky логотип
RLSA-2026:22644

Important: samba security update

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20905-1

Security update for samba

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2076-1

Security update for samba

2 месяца назад
rocky логотип
RLSA-2026:25049

Critical: samba security update

около 2 месяцев назад
rocky логотип
RLSA-2026:22963

Critical: samba security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-25049

ELSA-2026-25049: samba security update (CRITICAL)

около 1 месяца назад

Уязвимостей на страницу