Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25

Количество 25

debian логотип

CVE-2026-4408

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfigur ...

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-jg8v-92xc-cx65

2 месяца назад

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-hwwh-4hhw-h9jf

2 месяца назад

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 8.5
EPSS: Средний
fstec логотип

BDU:2026-07317

2 месяца назад

Уязвимость подсистемы печати (printing subsystem) программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Средний
fstec логотип

BDU:2026-07316

2 месяца назад

Уязвимость функции check password script модуля DCE/RPC SAMR server пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfigur ...

CVSS3: 9
3%
Низкий
2 месяца назад
github логотип
GHSA-jg8v-92xc-cx65

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

CVSS3: 9
3%
Низкий
2 месяца назад
github логотип
GHSA-hwwh-4hhw-h9jf

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

CVSS3: 8.5
14%
Средний
2 месяца назад
fstec логотип
BDU:2026-07317

Уязвимость подсистемы печати (printing subsystem) программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
14%
Средний
2 месяца назад
fstec логотип
BDU:2026-07316

Уязвимость функции check password script модуля DCE/RPC SAMR server пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
3%
Низкий
2 месяца назад

Уязвимостей на страницу