Количество 26
Количество 26
ELSA-2016-0011
ELSA-2016-0011: samba security update (MODERATE)

SUSE-SU-2016:0164-1
Security update for samba

SUSE-SU-2016:0032-1
Security update for samba
ELSA-2016-0010
ELSA-2016-0010: samba4 security update (MODERATE)
ELSA-2016-0006
ELSA-2016-0006: samba security update (MODERATE)

openSUSE-SU-2015:2354-1
Security update for ldb, samba, talloc, tdb, tevent

SUSE-SU-2015:2305-1
Security update for ldb, samba, talloc, tdb, tevent

SUSE-SU-2015:2304-1
Security update for ldb, samba, talloc, tdb, tevent

CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, ...
GHSA-v8hr-9qpr-jrwc
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

BDU:2021-01277
Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю оказать воздействие на целостность данных

CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.

CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.

CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_c ...

CVE-2015-5296
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.

CVE-2015-5296
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2016-0011 ELSA-2016-0011: samba security update (MODERATE) | больше 9 лет назад | |||
![]() | SUSE-SU-2016:0164-1 Security update for samba | больше 9 лет назад | ||
![]() | SUSE-SU-2016:0032-1 Security update for samba | больше 9 лет назад | ||
ELSA-2016-0010 ELSA-2016-0010: samba4 security update (MODERATE) | больше 9 лет назад | |||
ELSA-2016-0006 ELSA-2016-0006: samba security update (MODERATE) | больше 9 лет назад | |||
![]() | openSUSE-SU-2015:2354-1 Security update for ldb, samba, talloc, tdb, tevent | больше 9 лет назад | ||
![]() | SUSE-SU-2015:2305-1 Security update for ldb, samba, talloc, tdb, tevent | больше 9 лет назад | ||
![]() | SUSE-SU-2015:2304-1 Security update for ldb, samba, talloc, tdb, tevent | больше 9 лет назад | ||
![]() | CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS3: 7.2 | 26% Средний | больше 9 лет назад |
![]() | CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS2: 4.3 | 26% Средний | больше 9 лет назад |
![]() | CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS3: 7.2 | 26% Средний | больше 9 лет назад |
CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, ... | CVSS3: 7.2 | 26% Средний | больше 9 лет назад | |
GHSA-v8hr-9qpr-jrwc vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS3: 7.2 | 26% Средний | больше 3 лет назад | |
![]() | BDU:2021-01277 Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю оказать воздействие на целостность данных | CVSS3: 7.2 | 26% Средний | больше 9 лет назад |
![]() | CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. | CVSS3: 5.3 | 11% Средний | больше 9 лет назад |
![]() | CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. | CVSS2: 3.5 | 11% Средний | больше 9 лет назад |
![]() | CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. | CVSS3: 5.3 | 11% Средний | больше 9 лет назад |
CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_c ... | CVSS3: 5.3 | 11% Средний | больше 9 лет назад | |
![]() | CVE-2015-5296 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c. | CVSS3: 5.4 | 8% Низкий | больше 9 лет назад |
![]() | CVE-2015-5296 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c. | CVSS2: 5.8 | 8% Низкий | больше 9 лет назад |
Уязвимостей на страницу