Логотип exploitDog
bind:"BDU:2015-10377" OR bind:"CVE-2015-0240"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2015-10377" OR bind:"CVE-2015-0240"

Количество 13

Количество 13

fstec логотип

BDU:2015-10377

больше 10 лет назад

Уязвимость функции the _netr_ServerPasswordSet пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код c привилегиями администратора

CVSS3: 10
EPSS: Критический
ubuntu логотип

CVE-2015-0240

больше 10 лет назад

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS2: 10
EPSS: Критический
redhat логотип

CVE-2015-0240

больше 10 лет назад

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS2: 7.9
EPSS: Критический
nvd логотип

CVE-2015-0240

больше 10 лет назад

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS2: 10
EPSS: Критический
debian логотип

CVE-2015-0240

больше 10 лет назад

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x be ...

CVSS2: 10
EPSS: Критический
suse-cvrf логотип

SUSE-SU-2015:0371-1

больше 10 лет назад

Security update for Samba

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2015:0353-1

больше 10 лет назад

Security update for samba

EPSS: Критический
github логотип

GHSA-wjcr-wjqx-g6rq

больше 3 лет назад

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

EPSS: Критический
oracle-oval логотип

ELSA-2015-0252

больше 10 лет назад

ELSA-2015-0252: samba security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0251

больше 10 лет назад

ELSA-2015-0251: samba security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0250

больше 10 лет назад

ELSA-2015-0250: samba4 security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0249

больше 10 лет назад

ELSA-2015-0249: samba3x security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:0386-1

больше 11 лет назад

Security update for Samba

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2015-10377

Уязвимость функции the _netr_ServerPasswordSet пакета программ сетевого взаимодействия Samba, позволяющая нарушителю выполнить произвольный код c привилегиями администратора

CVSS3: 10
92%
Критический
больше 10 лет назад
ubuntu логотип
CVE-2015-0240

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS2: 10
92%
Критический
больше 10 лет назад
redhat логотип
CVE-2015-0240

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS2: 7.9
92%
Критический
больше 10 лет назад
nvd логотип
CVE-2015-0240

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

CVSS2: 10
92%
Критический
больше 10 лет назад
debian логотип
CVE-2015-0240

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x be ...

CVSS2: 10
92%
Критический
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0371-1

Security update for Samba

92%
Критический
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0353-1

Security update for samba

92%
Критический
больше 10 лет назад
github логотип
GHSA-wjcr-wjqx-g6rq

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

92%
Критический
больше 3 лет назад
oracle-oval логотип
ELSA-2015-0252

ELSA-2015-0252: samba security update (IMPORTANT)

больше 10 лет назад
oracle-oval логотип
ELSA-2015-0251

ELSA-2015-0251: samba security update (CRITICAL)

больше 10 лет назад
oracle-oval логотип
ELSA-2015-0250

ELSA-2015-0250: samba4 security update (CRITICAL)

больше 10 лет назад
oracle-oval логотип
ELSA-2015-0249

ELSA-2015-0249: samba3x security update (CRITICAL)

больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0386-1

Security update for Samba

больше 11 лет назад

Уязвимостей на страницу