Логотип exploitDog
bind:"CVE-2012-6150" OR bind:"CVE-2013-4496" OR bind:"CVE-2013-6442"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2012-6150" OR bind:"CVE-2013-4496" OR bind:"CVE-2013-6442"

Количество 41

Количество 41

oracle-oval логотип

ELSA-2014-0383

больше 11 лет назад

ELSA-2014-0383: samba4 security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2015-08932

больше 11 лет назад

Уязвимости операционной системы CentOS, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 8.3
EPSS: Низкий
fstec логотип

BDU:2015-06049

больше 11 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 8.3
EPSS: Низкий
oracle-oval логотип

ELSA-2014-0330

больше 11 лет назад

ELSA-2014-0330: samba and samba3x security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2012-6150

больше 11 лет назад

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

CVSS2: 3.6
EPSS: Низкий
redhat логотип

CVE-2012-6150

около 13 лет назад

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

CVSS2: 2.9
EPSS: Низкий
nvd логотип

CVE-2012-6150

больше 11 лет назад

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

CVSS2: 3.6
EPSS: Низкий
debian логотип

CVE-2012-6150

больше 11 лет назад

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winb ...

CVSS2: 3.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0386-1

больше 11 лет назад

Security update for Samba

EPSS: Низкий
github логотип

GHSA-65q8-2h4w-pqq6

около 3 лет назад

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

EPSS: Низкий
fstec логотип

BDU:2015-00390

больше 11 лет назад

Уязвимость программного обеспечения Samba, позволяющая удаленному злоумышленнику нарушить конфиденциальность и целостность защищаемой информации

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2013-6442

больше 11 лет назад

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2013-6442

больше 11 лет назад

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

CVSS2: 4.1
EPSS: Низкий
nvd логотип

CVE-2013-6442

больше 11 лет назад

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2013-6442

больше 11 лет назад

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-4496

больше 11 лет назад

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-4496

больше 11 лет назад

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

CVSS2: 3.8
EPSS: Низкий
nvd логотип

CVE-2013-4496

больше 11 лет назад

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-4496

больше 11 лет назад

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 d ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-qgqp-hrvv-cxc3

около 3 лет назад

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2014-0383

ELSA-2014-0383: samba4 security update (MODERATE)

больше 11 лет назад
fstec логотип
BDU:2015-08932

Уязвимости операционной системы CentOS, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 8.3
больше 11 лет назад
fstec логотип
BDU:2015-06049

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 8.3
больше 11 лет назад
oracle-oval логотип
ELSA-2014-0330

ELSA-2014-0330: samba and samba3x security update (MODERATE)

больше 11 лет назад
ubuntu логотип
CVE-2012-6150

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

CVSS2: 3.6
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2012-6150

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

CVSS2: 2.9
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-6150

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

CVSS2: 3.6
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2012-6150

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winb ...

CVSS2: 3.6
0%
Низкий
больше 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:0386-1

Security update for Samba

больше 11 лет назад
github логотип
GHSA-65q8-2h4w-pqq6

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuration-file mistake.

0%
Низкий
около 3 лет назад
fstec логотип
BDU:2015-00390

Уязвимость программного обеспечения Samba, позволяющая удаленному злоумышленнику нарушить конфиденциальность и целостность защищаемой информации

CVSS3: 4.4
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-6442

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2013-6442

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

CVSS2: 4.1
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-6442

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-6442

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before ...

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-4496

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

CVSS2: 5
5%
Низкий
больше 11 лет назад
redhat логотип
CVE-2013-4496

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

CVSS2: 3.8
5%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-4496

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

CVSS2: 5
5%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-4496

Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 d ...

CVSS2: 5
5%
Низкий
больше 11 лет назад
github логотип
GHSA-qgqp-hrvv-cxc3

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

1%
Низкий
около 3 лет назад

Уязвимостей на страницу