Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 36

Количество 36

suse-cvrf логотип

SUSE-SU-2023:3060-1

почти 3 года назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2930-1

около 3 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2888-1

около 3 лет назад

Security update for samba

EPSS: Низкий
rocky логотип

RLSA-2023:7139

около 1 месяца назад

Moderate: samba security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2023-7139

больше 2 лет назад

ELSA-2023-7139: samba security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6667

больше 2 лет назад

ELSA-2023-6667: samba security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2929-1

около 3 лет назад

Security update for samba

EPSS: Низкий
redos логотип

ROS-20230920-02

больше 2 лет назад

Множественные уязвимости samba

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20230920-01

больше 2 лет назад

Множественные уязвимости samba

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-2127

около 3 лет назад

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-2127

около 3 лет назад

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-2127

около 3 лет назад

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-2127

около 3 лет назад

An out-of-bounds read vulnerability was found in Samba due to insuffic ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3358-1

почти 3 года назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3017-1

около 3 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2887-1

около 3 лет назад

Security update for samba

EPSS: Низкий
github логотип

GHSA-mfwc-hx97-869v

около 3 лет назад

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2023-03963

около 3 лет назад

Уязвимость компонента winbindd_pam_auth_crap.c пакета программ сетевого взаимодействия Samba, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-34966

около 3 лет назад

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2023-34966

около 3 лет назад

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2023:3060-1

Security update for samba

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:2930-1

Security update for samba

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2888-1

Security update for samba

около 3 лет назад
rocky логотип
RLSA-2023:7139

Moderate: samba security, bug fix, and enhancement update

около 1 месяца назад
oracle-oval логотип
ELSA-2023-7139

ELSA-2023-7139: samba security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-6667

ELSA-2023-6667: samba security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2929-1

Security update for samba

около 3 лет назад
redos логотип
ROS-20230920-02

Множественные уязвимости samba

CVSS3: 7.5
больше 2 лет назад
redos логотип
ROS-20230920-01

Множественные уязвимости samba

CVSS3: 7.5
больше 2 лет назад
ubuntu логотип
CVE-2022-2127

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-2127

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-2127

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
2%
Низкий
около 3 лет назад
debian логотип
CVE-2022-2127

An out-of-bounds read vulnerability was found in Samba due to insuffic ...

CVSS3: 5.9
2%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3358-1

Security update for samba

2%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:3017-1

Security update for samba

2%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2887-1

Security update for samba

2%
Низкий
около 3 лет назад
github логотип
GHSA-mfwc-hx97-869v

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.

CVSS3: 5.9
2%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-03963

Уязвимость компонента winbindd_pam_auth_crap.c пакета программ сетевого взаимодействия Samba, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
2%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-34966

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.

CVSS3: 7.5
60%
Средний
около 3 лет назад
redhat логотип
CVE-2023-34966

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing 0 as the count value, the attacked function will run in an endless loop consuming 100% CPU. This flaw allows an attacker to issue a malformed RPC request, triggering an infinite loop, resulting in a denial of service condition.

CVSS3: 7.5
60%
Средний
около 3 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.