Количество 26
Количество 26
ELSA-2016-0011
ELSA-2016-0011: samba security update (MODERATE)
SUSE-SU-2016:0164-1
Security update for samba
SUSE-SU-2016:0032-1
Security update for samba
ELSA-2016-0010
ELSA-2016-0010: samba4 security update (MODERATE)
ELSA-2016-0006
ELSA-2016-0006: samba security update (MODERATE)
openSUSE-SU-2015:2354-1
Security update for ldb, samba, talloc, tdb, tevent
SUSE-SU-2015:2305-1
Security update for ldb, samba, talloc, tdb, tevent
SUSE-SU-2015:2304-1
Security update for ldb, samba, talloc, tdb, tevent
CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
CVE-2015-5252
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, ...
GHSA-v8hr-9qpr-jrwc
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.
BDU:2021-01277
Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю оказать воздействие на целостность данных
CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
CVE-2015-5299
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_c ...
CVE-2015-5296
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
CVE-2015-5296
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2016-0011 ELSA-2016-0011: samba security update (MODERATE) | около 10 лет назад | |||
SUSE-SU-2016:0164-1 Security update for samba | около 10 лет назад | |||
SUSE-SU-2016:0032-1 Security update for samba | около 10 лет назад | |||
ELSA-2016-0010 ELSA-2016-0010: samba4 security update (MODERATE) | около 10 лет назад | |||
ELSA-2016-0006 ELSA-2016-0006: samba security update (MODERATE) | около 10 лет назад | |||
openSUSE-SU-2015:2354-1 Security update for ldb, samba, talloc, tdb, tevent | около 10 лет назад | |||
SUSE-SU-2015:2305-1 Security update for ldb, samba, talloc, tdb, tevent | около 10 лет назад | |||
SUSE-SU-2015:2304-1 Security update for ldb, samba, talloc, tdb, tevent | около 10 лет назад | |||
CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS3: 7.2 | 17% Средний | около 10 лет назад | |
CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS2: 4.3 | 17% Средний | около 10 лет назад | |
CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS3: 7.2 | 17% Средний | около 10 лет назад | |
CVE-2015-5252 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, ... | CVSS3: 7.2 | 17% Средний | около 10 лет назад | |
GHSA-v8hr-9qpr-jrwc vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share. | CVSS3: 7.2 | 17% Средний | больше 3 лет назад | |
BDU:2021-01277 Уязвимость библиотеки smbd пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю оказать воздействие на целостность данных | CVSS3: 7.2 | 17% Средний | около 10 лет назад | |
CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. | CVSS3: 5.3 | 8% Низкий | около 10 лет назад | |
CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. | CVSS2: 3.5 | 8% Низкий | около 10 лет назад | |
CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory. | CVSS3: 5.3 | 8% Низкий | около 10 лет назад | |
CVE-2015-5299 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_c ... | CVSS3: 5.3 | 8% Низкий | около 10 лет назад | |
CVE-2015-5296 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c. | CVSS3: 5.4 | 3% Низкий | около 10 лет назад | |
CVE-2015-5296 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c. | CVSS2: 5.8 | 3% Низкий | около 10 лет назад |
Уязвимостей на страницу