Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 36

Количество 36

oracle-oval логотип

ELSA-2020-1878

больше 6 лет назад

ELSA-2020-1878: samba security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-1084

больше 6 лет назад

ELSA-2020-1084: samba security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2673-1

почти 6 лет назад

Security update for samba

EPSS: Низкий
ubuntu логотип

CVE-2019-10197

почти 7 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10197

почти 7 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-10197

почти 7 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10197

почти 7 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2142-1

почти 7 лет назад

Security update for samba

EPSS: Низкий
github логотип

GHSA-v6g6-jxr8-2r44

около 4 лет назад

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2019-03211

почти 7 лет назад

Уязвимость SMB-сервера (файл конфигурации smb.conf) пакета программ для сетевого взаимодействия Samba, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-14907

больше 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-14907

больше 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-14907

больше 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-14907

больше 6 лет назад

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11 ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10218

почти 7 лет назад

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10218

почти 7 лет назад

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-10218

почти 7 лет назад

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-10218

почти 7 лет назад

A flaw was found in the samba client, all samba versions before samba ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0233-1

больше 6 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0152-1

больше 6 лет назад

Security update for samba

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-1878

ELSA-2020-1878: samba security, bug fix, and enhancement update (MODERATE)

больше 6 лет назад
oracle-oval логотип
ELSA-2020-1084

ELSA-2020-1084: samba security, bug fix, and enhancement update (MODERATE)

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:2673-1

Security update for samba

почти 6 лет назад
ubuntu логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
3%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
3%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 6.5
3%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10197

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up ...

CVSS3: 6.5
3%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2142-1

Security update for samba

3%
Низкий
почти 7 лет назад
github логотип
GHSA-v6g6-jxr8-2r44

A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

CVSS3: 9.1
3%
Низкий
около 4 лет назад
fstec логотип
BDU:2019-03211

Уязвимость SMB-сервера (файл конфигурации smb.conf) пакета программ для сетевого взаимодействия Samba, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
3%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).

CVSS3: 6.5
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11 ...

CVSS3: 6.5
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 5.3
4%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

CVSS3: 6.5
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10218

A flaw was found in the samba client, all samba versions before samba ...

CVSS3: 6.5
4%
Низкий
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2020:0233-1

Security update for samba

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0152-1

Security update for samba

3%
Низкий
больше 6 лет назад

Уязвимостей на страницу