Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Samba MEDIUM 6.8
CVE-2007-0452

smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in …

Mitigation only
Fix from $1,600 2007-02-06
Samba MEDIUM 5.0
CVE-2006-3403EPSS 6%

The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large …

Patch available
Fix from $1,600 2006-07-12
Samba MEDIUM 6.4
CVE-2004-2546

Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).

Mitigation only
Fix from $1,600 2004-12-31
Samba MEDIUM 5.0
CVE-2004-0808EPSS 5%

The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a …

Patch available
Fix from $1,600 2004-12-31
Samba MEDIUM 5.0
CVE-2004-0829

smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request withou…

Patch available
Fix from $1,600 2004-12-31
Samba HIGH 7.5
CVE-2004-0815

The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down to absolute paths, which coul…

Patch available
Fix from $1,950 2004-11-03
Samba HIGH 10.0
CVE-2004-0600EPSS 29%

Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid …

Patch available
Fix from $1,950 2004-07-27
Samba MEDIUM 5.0
CVE-2004-0686

Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and …

Fix: 2.2.10 / 3.0.5+
Fix from $1,600 2004-07-27
Samba HIGH 7.5
CVE-2004-0082

The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user p…

Patch available
Fix from $1,950 2004-03-03
Jitterbug HIGH 7.5
CVE-2004-0028

jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.

Patch available
Fix from $1,950 2004-02-03
Samba HIGH 7.5
CVE-2003-1332

Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted…

Fix: after 2.2.7a
Fix from $1,950 2003-12-31
Samba HIGH 10.0
CVE-2003-0196EPSS 23%

Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by …

Patch available
Fix from $1,950 2003-05-05
Samba HIGH 10.0
CVE-2003-0201EPSS 85%

Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.…

Patch available
Fix from $1,950 2003-05-05
Samba HIGH 10.0
CVE-2003-0085EPSS 88%

Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remo…

Patch available
Fix from $1,950 2003-03-31
Samba HIGH 7.5
CVE-2002-2196EPSS 7%

Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a b…

Fix: after 2.2.4
Fix from $1,950 2002-12-31
Samba HIGH 10.0
CVE-2002-1318EPSS 52%

Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypte…

Patch available
Fix from $1,950 2002-12-11
Samba HIGH 10.0
CVE-2001-1162EPSS 12%

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite cert…

Patch available
Fix from $1,950 2001-06-23
Samba HIGH 7.5
CVE-2000-0937EPSS 8%

Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which all…

Patch available
Fix from $1,950 2000-12-19
Samba HIGH 7.2
CVE-2000-0935

Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.

Patch available
Fix from $1,950 2000-12-19
Samba MEDIUM 5.0
CVE-2000-0938

Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, whic…

Patch available
Fix from $1,600 2000-12-19
Samba MEDIUM 5.0
CVE-2000-0939

Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL i…

Patch available
Fix from $1,600 2000-12-19
Samba HIGH 7.6
CVE-1999-0812

Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.

Mitigation only
Fix from $1,950 2000-07-12
Samba HIGH 10.0
CVE-1999-0810

Denial of service in Samba NETBIOS name service daemon (nmbd).

No fix yet
Fix from $1,950 1999-07-21
Samba MEDIUM 5.0
CVE-1999-0811

Buffer overflow in Samba smbd program via a malformed message command.

Mitigation only
Fix from $1,600 1999-07-21
Samba HIGH 10.0
CVE-1999-0182EPSS 10%

Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.

Fix: after 1.9.17
Fix from $1,950 1997-09-30