Количество 25
Количество 25
ELSA-2026-28132
ELSA-2026-28132: samba security update (IMPORTANT)
ELSA-2026-22644
ELSA-2026-22644: samba security update (IMPORTANT)
SUSE-SU-2026:2108-1
Security update for samba
SUSE-SU-2026:2073-1
Security update for samba
SUSE-SU-2026:2074-1
Security update for samba
SUSE-SU-2026:2072-1
Security update for samba
RLSA-2026:22644
Important: samba security update
openSUSE-SU-2026:20905-1
Security update for samba
SUSE-SU-2026:2076-1
Security update for samba
RLSA-2026:25049
Critical: samba security update
RLSA-2026:22963
Critical: samba security update
ELSA-2026-25049
ELSA-2026-25049: samba security update (CRITICAL)
ELSA-2026-22963
ELSA-2026-22963: samba security update (CRITICAL)
CVE-2026-4480
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
CVE-2026-4480
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
CVE-2026-4480
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.
CVE-2026-4480
A flaw was found in the Samba printing subsystem. Samba passes the cli ...
CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
CVE-2026-4408
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2026-28132 ELSA-2026-28132: samba security update (IMPORTANT) | 11 дней назад | |||
ELSA-2026-22644 ELSA-2026-22644: samba security update (IMPORTANT) | около 2 месяцев назад | |||
SUSE-SU-2026:2108-1 Security update for samba | 2 месяца назад | |||
SUSE-SU-2026:2073-1 Security update for samba | 2 месяца назад | |||
SUSE-SU-2026:2074-1 Security update for samba | 2 месяца назад | |||
SUSE-SU-2026:2072-1 Security update for samba | 2 месяца назад | |||
RLSA-2026:22644 Important: samba security update | около 2 месяцев назад | |||
openSUSE-SU-2026:20905-1 Security update for samba | около 2 месяцев назад | |||
SUSE-SU-2026:2076-1 Security update for samba | 2 месяца назад | |||
RLSA-2026:25049 Critical: samba security update | около 2 месяцев назад | |||
RLSA-2026:22963 Critical: samba security update | около 2 месяцев назад | |||
ELSA-2026-25049 ELSA-2026-25049: samba security update (CRITICAL) | около 1 месяца назад | |||
ELSA-2026-22963 ELSA-2026-22963: samba security update (CRITICAL) | 17 дней назад | |||
CVE-2026-4480 A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system. | CVSS3: 9 | 14% Средний | 2 месяца назад | |
CVE-2026-4480 A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system. | CVSS3: 9 | 14% Средний | 2 месяца назад | |
CVE-2026-4480 A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system. | CVSS3: 9 | 14% Средний | 2 месяца назад | |
CVE-2026-4480 A flaw was found in the Samba printing subsystem. Samba passes the cli ... | CVSS3: 9 | 14% Средний | 2 месяца назад | |
CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service. | CVSS3: 9 | 3% Низкий | 2 месяца назад | |
CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service. | CVSS3: 9 | 3% Низкий | 2 месяца назад | |
CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service. | CVSS3: 9 | 3% Низкий | 2 месяца назад |
Уязвимостей на страницу