Search CVE reports
131 – 140 of 187 results
CVE-2013-4408
Medium prioritySome fixes available 12 of 17
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to...
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Fixed |
samba4 | — | — | — | — | Not in release |
CVE-2012-6150
Medium prioritySome fixes available 12 of 17
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users...
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Fixed |
samba4 | — | — | — | — | Not in release |
CVE-2013-4476
Medium prioritySamba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as...
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Not affected |
samba4 | — | — | — | — | Not in release |
CVE-2013-4475
Low prioritySome fixes available 12 of 17
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL...
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Fixed |
samba4 | — | — | — | — | Not in release |
CVE-2013-4124
Medium prioritySome fixes available 4 of 9
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a...
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Not affected |
samba4 | — | — | — | — | Not in release |
CVE-2013-0454
Medium priorityThe SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows...
1 affected package
samba
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | — |
CVE-2013-1863
High prioritySamba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary...
1 affected package
samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba4 | — | — | — | — | Not in release |
CVE-2013-0214
Medium prioritySome fixes available 1 of 10
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary...
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Not affected |
samba4 | — | — | — | — | Not in release |
CVE-2013-0213
Medium prioritySome fixes available 1 of 10
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
2 affected packages
samba, samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba | — | — | — | — | Not affected |
samba4 | — | — | — | — | Not in release |
CVE-2013-0172
Medium prioritySamba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to...
1 affected package
samba4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
samba4 | — | — | — | — | Not in release |