Samba kayıtları
samba üreticisine ait 266 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,8
- Silahlaştırılmış
- 12 · %4,5
- Pre-auth RCE
- 30
- Düzeltme kaydı olan
- %92,1
- Yayından KEV’e ortanca
- 1287 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-20 Improper Input Validation17
- CWE-264 Permissions, Privileges, and Access Controls13
- CWE-125 Out-of-bounds Read11
- CWE-59 Improper Link Resolution Before File Access ('Link Following')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
266 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2017-7494Silahlaştırılmış | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Kritik9,8 | KEV | %99,4 | 30 May 2017 |
82Hemen | CVE-2020-1472Silahlaştırılmış | Netlogon Elevation of Privilege Vulnerabilitymicrosoft · windows server 1903 | Orta5,5 | KEV | %99,4 | 17 Ağu 2020 |
66Bu hafta | CVE-2015-0240Silahlaştırılmış | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x beforsamba · samba · CWE-17 | Kritik10,0 | — | %88,0 | 23 Şub 2015 |
66Bu hafta | CVE-2003-0085Kavram kanıtı | Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, alsamba · samba | Kritik10,0 | — | %86,4 | 31 Mar 2003 |
65Bu hafta | CVE-2003-0201Silahlaştırılmış | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Kritik10,0 | — | %84,5 | 5 May 2003 |
63Bu hafta | CVE-2004-2687Silahlaştırılmış | distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute aapple · xcode · CWE-16 | Kritik9,3 | — | %88,2 | 31 Ara 2004 |
63Bu hafta | CVE-2007-2446Silahlaştırılmış | Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrarysamba · samba · CWE-119 | Kritik10,0 | — | %77,7 | 14 May 2007 |
62Bu hafta | CVE-2012-1182Silahlaştırılmış | The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array lensamba · samba · CWE-189 | Kritik10,0 | — | %74,4 | 10 Nis 2012 |
61Bu hafta | CVE-2024-12084Kavram kanıtı | Rsync: heap buffer overflow in rsync due to improper checksum length handlingsamba · rsync · CWE-122 | Kritik9,8 | — | %72,1 | 15 Oca 2025 |
57Planlayın | CVE-2021-44142Kavram kanıtı | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interosamba · samba · CWE-125 | Yüksek8,8 | — | %73,4 | 21 Şub 2022 |
56Planlayın | CVE-2002-1318Silahlaştırılmış | Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via ansamba · samba | Kritik10,0 | — | %51,9 | 11 Ara 2002 |
54Planlayın | CVE-2010-2063Silahlaştırılmış | Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allsamba · samba · CWE-119 | Yüksek7,5 | — | %78,6 | 17 Haz 2010 |
51Planlayın | CVE-2008-1105Kavram kanıtı | Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute asamba · samba · CWE-119 | Yüksek7,5 | — | %69,1 | 29 May 2008 |
49Planlayın | CVE-2023-34966İstismar yok | Samba: infinite loop in mdssvc rpc service for spotlightsamba · samba · CWE-835 | Yüksek7,5 | — | %62,4 | 20 Tem 2023 |
49Planlayın | CVE-2004-0600Kavram kanıtı | Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via ansamba · samba | Kritik10,0 | — | %29,4 | 27 Tem 2004 |
48Planlayın | CVE-2014-3560İstismar yok | NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code vsamba · samba · CWE-94 | Yüksek7,9 | — | %56,4 | 6 Ağu 2014 |
47Planlayın | CVE-2003-0196İstismar yok | Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discosamba · samba | Kritik10,0 | — | %22,8 | 5 May 2003 |
45Planlayın | CVE-2007-6015Kavram kanıtı | Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabledsamba · samba · CWE-119 | Kritik9,3 | — | %27,5 | 13 Ara 2007 |
44Planlayın | CVE-2004-0882İstismar yok | Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via asamba · samba | Kritik10,0 | — | %13,7 | 27 Oca 2005 |
44Planlayın | CVE-2004-1154İstismar yok | Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of servsamba · samba | Kritik10,0 | — | %13,2 | 10 Oca 2005 |
44Planlayın | CVE-2001-1162Kavram kanıtı | Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwsamba · samba | Kritik10,0 | — | %12,0 | 23 Haz 2001 |
43Planlayın | CVE-1999-0182Kavram kanıtı | Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.samba · samba | Kritik10,0 | — | %9,7 | 30 Eyl 1997 |
42Planlayın | CVE-2017-14746İstismar yok | Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.samba · samba · CWE-416 | Kritik9,8 | — | %9,9 | 27 Kas 2017 |
41Planlayın | CVE-2013-4124Silahlaştırılmış | Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4samba · samba · CWE-189 | Orta5,0 | — | %69,0 | 5 Ağu 2013 |
41Planlayın | CVE-2016-2118Kavram kanıtı | The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCsamba · samba · CWE-254 | Yüksek7,5 | — | %36,9 | 12 Nis 2016 |
- CVE-2017-749499Hemen
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99samba · samba30 May 2017
- CVE-2020-147282Hemen
Netlogon Elevation of Privilege Vulnerability
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %99microsoft · windows server 190317 Ağu 2020
- CVE-2015-024066Bu hafta
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x befor
KritikCVSS 10,0SilahlaştırılmışEPSS %88samba · samba23 Şub 2015
- CVE-2003-008566Bu hafta
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, al
KritikCVSS 10,0Kavram kanıtıEPSS %86samba · samba31 Mar 2003
- CVE-2003-020165Bu hafta
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
KritikCVSS 10,0SilahlaştırılmışEPSS %85samba · samba5 May 2003
- CVE-2004-268763Bu hafta
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute a
KritikCVSS 9,3SilahlaştırılmışEPSS %88apple · xcode31 Ara 2004
- CVE-2007-244663Bu hafta
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary
KritikCVSS 10,0SilahlaştırılmışEPSS %78samba · samba14 May 2007
- CVE-2012-118262Bu hafta
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array len
KritikCVSS 10,0SilahlaştırılmışEPSS %74samba · samba10 Nis 2012
- CVE-2024-1208461Bu hafta
Rsync: heap buffer overflow in rsync due to improper checksum length handling
KritikCVSS 9,8Kavram kanıtıEPSS %72samba · rsync15 Oca 2025
- CVE-2021-4414257Planlayın
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero
YüksekCVSS 8,8Kavram kanıtıEPSS %73samba · samba21 Şub 2022
- CVE-2002-131856Planlayın
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an
KritikCVSS 10,0SilahlaştırılmışEPSS %52samba · samba11 Ara 2002
- CVE-2010-206354Planlayın
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 all
YüksekCVSS 7,5SilahlaştırılmışEPSS %79samba · samba17 Haz 2010
- CVE-2008-110551Planlayın
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute a
YüksekCVSS 7,5Kavram kanıtıEPSS %69samba · samba29 May 2008
- CVE-2023-3496649Planlayın
Samba: infinite loop in mdssvc rpc service for spotlight
YüksekCVSS 7,5İstismar yokEPSS %62samba · samba20 Tem 2023
- CVE-2004-060049Planlayın
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an
KritikCVSS 10,0Kavram kanıtıEPSS %29samba · samba27 Tem 2004
- CVE-2014-356048Planlayın
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code v
YüksekCVSS 7,9İstismar yokEPSS %56samba · samba6 Ağu 2014
- CVE-2003-019647Planlayın
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as disco
KritikCVSS 10,0İstismar yokEPSS %23samba · samba5 May 2003
- CVE-2007-601545Planlayın
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled
KritikCVSS 9,3Kavram kanıtıEPSS %27samba · samba13 Ara 2007
- CVE-2004-088244Planlayın
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a
KritikCVSS 10,0İstismar yokEPSS %14samba · samba27 Oca 2005
- CVE-2004-115444Planlayın
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of serv
KritikCVSS 10,0İstismar yokEPSS %13samba · samba10 Oca 2005
- CVE-2001-116244Planlayın
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overw
KritikCVSS 10,0Kavram kanıtıEPSS %12samba · samba23 Haz 2001
- CVE-1999-018243Planlayın
Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.
KritikCVSS 10,0Kavram kanıtıEPSS %10samba · samba30 Eyl 1997
- CVE-2017-1474642Planlayın
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
KritikCVSS 9,8İstismar yokEPSS %10samba · samba27 Kas 2017
- CVE-2013-412441Planlayın
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4
OrtaCVSS 5,0SilahlaştırılmışEPSS %69samba · samba5 Ağu 2013
- CVE-2016-211841Planlayın
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DC
YüksekCVSS 7,5Kavram kanıtıEPSS %37samba · samba12 Nis 2016