Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Samba MEDIUM 5.3
CVE-2015-3223EPSS 7%

The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, …

Mitigation only
Fix from $1,600 2015-12-29
Rsync MEDIUM 6.4
CVE-2014-9512EPSS 6%

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

No fix yet
Fix from $1,600 2015-02-12
Samba HIGH 8.5
CVE-2014-8143

Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows rem…

Patch available
Fix from $1,950 2015-01-17
Samba MEDIUM 5.0
CVE-2014-0239EPSS 67%

The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a resp…

Fix: 4.0.18 / 4.1.8+
Fix from $1,600 2014-05-28
Rsync HIGH 7.8
CVE-2014-2855

The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU co…

Fix: after 3.1.0
Fix from $1,950 2014-04-23
Samba MEDIUM 5.8
CVE-2013-6442

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgr…

Mitigation only
Fix from $1,600 2014-03-14
Samba HIGH 8.3
CVE-2013-4408

Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x be…

Patch available
Fix from $1,950 2013-12-10
Samba MEDIUM 6.0
CVE-2013-1863

Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which a…

Patch available
Fix from $1,600 2013-03-19
Samba MEDIUM 5.1
CVE-2013-0213

The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct cli…

Mitigation only
Fix from $1,600 2013-02-02
Samba MEDIUM 5.1
CVE-2013-0214

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x …

Mitigation only
Fix from $1,600 2013-02-02
Samba MEDIUM 6.5
CVE-2012-2111

The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.…

Patch available
Fix from $1,600 2012-04-30
Samba HIGH 10.0
CVE-2012-1182EPSS 74%

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a …

Fix: after 3.4.15
Fix from $1,950 2012-04-10
Samba HIGH 7.9
CVE-2012-0870EPSS 6%

Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971…

Fix: after 2.0
Fix from $1,950 2012-02-23
Samba MEDIUM 5.0
CVE-2012-0817

Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many conn…

Patch available
Fix from $1,600 2012-01-30
Samba HIGH 9.0
CVE-2011-2411EPSS 6%

Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote …

Mitigation only
Fix from $1,950 2011-10-02
Rsync MEDIUM 5.1
CVE-2011-1097

rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (h…

Patch available
Fix from $1,600 2011-03-30
Samba MEDIUM 5.0
CVE-2011-0719

Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macr…

Patch available
Fix from $1,600 2011-03-01
Samba MEDIUM 5.0
CVE-2010-1635

The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL…

Fix: after 3.4.7
Fix from $1,600 2010-06-17
Samba MEDIUM 5.0
CVE-2010-1642

The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an o…

Fix: after 3.4.7
Fix from $1,600 2010-06-17
Samba HIGH 8.5
CVE-2010-0728

smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated …

Mitigation only
Fix from $1,950 2010-03-10
Samba HIGH 9.3
CVE-2009-1886EPSS 12%

Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execu…

Patch available
Fix from $1,950 2009-06-25
Samba MEDIUM 6.3
CVE-2009-0022

Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection…

Patch available
Fix from $1,600 2009-01-05
Samba HIGH 8.5
CVE-2008-4314

smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) tra…

Patch available
Fix from $1,950 2008-12-01
Rsync HIGH 7.5
CVE-2008-1720

Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via …

Patch available
Fix from $1,950 2008-04-10
Samba HIGH 9.3
CVE-2007-6015EPSS 27%

Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows …

Patch available
Fix from $1,950 2007-12-13
Samba HIGH 9.3
CVE-2007-4572EPSS 6%

Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers…

Patch available
Fix from $1,950 2007-11-16
Samba HIGH 9.3
CVE-2007-5398EPSS 11%

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a W…

Mitigation only
Fix from $1,950 2007-11-16
Samba MEDIUM 6.9
CVE-2007-4138

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc…

Patch available
Fix from $1,600 2007-09-14
Samba HIGH 10.0
CVE-2007-2446EPSS 77%

Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via…

Patch available
Fix from $1,950 2007-05-14
Samba MEDIUM 6.0
CVE-2007-2447EPSS 50%

The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters invo…

Patch available
Fix from $1,600 2007-05-14