Логотип exploitDog
bind:"CVE-2019-10197" OR bind:"CVE-2019-14907" OR bind:"CVE-2019-10218"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-10197" OR bind:"CVE-2019-14907" OR bind:"CVE-2019-10218"

Количество 36

Количество 36

oracle-oval логотип

ELSA-2020-1878

почти 6 лет назад

ELSA-2020-1878: samba security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-1084

почти 6 лет назад

ELSA-2020-1084: samba security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2673-1

больше 5 лет назад

Security update for samba

EPSS: Низкий
ubuntu логотип

CVE-2019-10197

больше 6 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10197

больше 6 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-10197

больше 6 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10197

больше 6 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2142-1

больше 6 лет назад

Security update for samba

EPSS: Низкий
github логотип

GHSA-v6g6-jxr8-2r44

больше 3 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2019-03211

больше 6 лет назад

Уязвимость SMB-сервера (файл конфигурации smb.conf) пакета программ для сетевого взаимодействия Samba, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14907

около 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2019-14907

около 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-14907

около 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-14907

около 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11 ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2019-10218

больше 6 лет назад

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10218

больше 6 лет назад

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-10218

больше 6 лет назад

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10218

больше 6 лет назад

A flaw was found in the samba client, all samba versions before samba ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0233-1

около 6 лет назад

Security update for samba

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2020:0152-1

около 6 лет назад

Security update for samba

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-1878

ELSA-2020-1878: samba security, bug fix, and enhancement update (MODERATE)

почти 6 лет назад
oracle-oval логотип
ELSA-2020-1084

ELSA-2020-1084: samba security, bug fix, and enhancement update (MODERATE)

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:2673-1

Security update for samba

больше 5 лет назад
ubuntu логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up ...

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2142-1

Security update for samba

5%
Низкий
больше 6 лет назад
github логотип
GHSA-v6g6-jxr8-2r44

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 9.1
5%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-03211

Уязвимость SMB-сервера (файл конфигурации smb.conf) пакета программ для сетевого взаимодействия Samba, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
5%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
10%
Средний
около 6 лет назад
redhat логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
10%
Средний
около 6 лет назад
nvd логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
10%
Средний
около 6 лет назад
debian логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11 ...

CVSS3: 6.5
10%
Средний
около 6 лет назад
ubuntu логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 5.3
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba ...

CVSS3: 6.5
5%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0233-1

Security update for samba

10%
Средний
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0152-1

Security update for samba

10%
Средний
около 6 лет назад

Уязвимостей на страницу