Записи Samba
266 опубликованных записей вендора samba.
Профиль для исследователя
- Попали в KEV
- 2 · 0,8 %
- С эксплойтом
- 12 · 4,5 %
- Pre-auth RCE
- 30
- С записью об исправлении
- 92,1 %
- Медиана: публикация → KEV
- 1287 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-20 Improper Input Validation17
- CWE-264 Permissions, Privileges, and Access Controls13
- CWE-125 Out-of-bounds Read11
- CWE-59 Improper Link Resolution Before File Access ('Link Following')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
266 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2017-7494Готовый эксплойт | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Критическая9,8 | KEV | 99,4 % | 30 мая 2017 г. |
82Срочно | CVE-2020-1472Готовый эксплойт | Netlogon Elevation of Privilege Vulnerabilitymicrosoft · windows server 1903 | Средняя5,5 | KEV | 99,4 % | 17 авг. 2020 г. |
66На этой неделе | CVE-2015-0240Готовый эксплойт | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x beforsamba · samba · CWE-17 | Критическая10,0 | — | 88,0 % | 23 февр. 2015 г. |
66На этой неделе | CVE-2003-0085Proof of concept | Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, alsamba · samba | Критическая10,0 | — | 86,4 % | 31 мар. 2003 г. |
65На этой неделе | CVE-2003-0201Готовый эксплойт | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Критическая10,0 | — | 84,5 % | 5 мая 2003 г. |
63На этой неделе | CVE-2004-2687Готовый эксплойт | distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute aapple · xcode · CWE-16 | Критическая9,3 | — | 88,2 % | 31 дек. 2004 г. |
63На этой неделе | CVE-2007-2446Готовый эксплойт | Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrarysamba · samba · CWE-119 | Критическая10,0 | — | 77,7 % | 14 мая 2007 г. |
62На этой неделе | CVE-2012-1182Готовый эксплойт | The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array lensamba · samba · CWE-189 | Критическая10,0 | — | 74,4 % | 10 апр. 2012 г. |
61На этой неделе | CVE-2024-12084Proof of concept | Rsync: heap buffer overflow in rsync due to improper checksum length handlingsamba · rsync · CWE-122 | Критическая9,8 | — | 72,1 % | 15 янв. 2025 г. |
57В плане | CVE-2021-44142Proof of concept | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interosamba · samba · CWE-125 | Высокая8,8 | — | 73,4 % | 21 февр. 2022 г. |
56В плане | CVE-2002-1318Готовый эксплойт | Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via ansamba · samba | Критическая10,0 | — | 51,9 % | 11 дек. 2002 г. |
54В плане | CVE-2010-2063Готовый эксплойт | Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allsamba · samba · CWE-119 | Высокая7,5 | — | 78,6 % | 17 июн. 2010 г. |
51В плане | CVE-2008-1105Proof of concept | Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute asamba · samba · CWE-119 | Высокая7,5 | — | 69,1 % | 29 мая 2008 г. |
49В плане | CVE-2023-34966Эксплойта нет | Samba: infinite loop in mdssvc rpc service for spotlightsamba · samba · CWE-835 | Высокая7,5 | — | 62,4 % | 20 июл. 2023 г. |
49В плане | CVE-2004-0600Proof of concept | Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via ansamba · samba | Критическая10,0 | — | 29,4 % | 27 июл. 2004 г. |
48В плане | CVE-2014-3560Эксплойта нет | NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code vsamba · samba · CWE-94 | Высокая7,9 | — | 56,4 % | 6 авг. 2014 г. |
47В плане | CVE-2003-0196Эксплойта нет | Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discosamba · samba | Критическая10,0 | — | 22,8 % | 5 мая 2003 г. |
45В плане | CVE-2007-6015Proof of concept | Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabledsamba · samba · CWE-119 | Критическая9,3 | — | 27,5 % | 13 дек. 2007 г. |
44В плане | CVE-2004-0882Эксплойта нет | Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via asamba · samba | Критическая10,0 | — | 13,7 % | 27 янв. 2005 г. |
44В плане | CVE-2004-1154Эксплойта нет | Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of servsamba · samba | Критическая10,0 | — | 13,2 % | 10 янв. 2005 г. |
44В плане | CVE-2001-1162Proof of concept | Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwsamba · samba | Критическая10,0 | — | 12,0 % | 23 июн. 2001 г. |
43В плане | CVE-1999-0182Proof of concept | Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.samba · samba | Критическая10,0 | — | 9,7 % | 30 сент. 1997 г. |
42В плане | CVE-2017-14746Эксплойта нет | Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.samba · samba · CWE-416 | Критическая9,8 | — | 9,9 % | 27 нояб. 2017 г. |
41В плане | CVE-2013-4124Готовый эксплойт | Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4samba · samba · CWE-189 | Средняя5,0 | — | 69,0 % | 5 авг. 2013 г. |
41В плане | CVE-2016-2118Proof of concept | The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCsamba · samba · CWE-254 | Высокая7,5 | — | 36,9 % | 12 апр. 2016 г. |
- CVE-2017-749499Срочно
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %samba · samba30 мая 2017 г.
- CVE-2020-147282Срочно
Netlogon Elevation of Privilege Vulnerability
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 99 %microsoft · windows server 190317 авг. 2020 г.
- CVE-2015-024066На этой неделе
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x befor
КритическаяCVSS 10,0Готовый эксплойтEPSS 88 %samba · samba23 февр. 2015 г.
- CVE-2003-008566На этой неделе
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, al
КритическаяCVSS 10,0Proof of conceptEPSS 86 %samba · samba31 мар. 2003 г.
- CVE-2003-020165На этой неделе
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
КритическаяCVSS 10,0Готовый эксплойтEPSS 85 %samba · samba5 мая 2003 г.
- CVE-2004-268763На этой неделе
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute a
КритическаяCVSS 9,3Готовый эксплойтEPSS 88 %apple · xcode31 дек. 2004 г.
- CVE-2007-244663На этой неделе
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary
КритическаяCVSS 10,0Готовый эксплойтEPSS 78 %samba · samba14 мая 2007 г.
- CVE-2012-118262На этой неделе
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array len
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %samba · samba10 апр. 2012 г.
- CVE-2024-1208461На этой неделе
Rsync: heap buffer overflow in rsync due to improper checksum length handling
КритическаяCVSS 9,8Proof of conceptEPSS 72 %samba · rsync15 янв. 2025 г.
- CVE-2021-4414257В плане
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and intero
ВысокаяCVSS 8,8Proof of conceptEPSS 73 %samba · samba21 февр. 2022 г.
- CVE-2002-131856В плане
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an
КритическаяCVSS 10,0Готовый эксплойтEPSS 52 %samba · samba11 дек. 2002 г.
- CVE-2010-206354В плане
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 all
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %samba · samba17 июн. 2010 г.
- CVE-2008-110551В плане
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute a
ВысокаяCVSS 7,5Proof of conceptEPSS 69 %samba · samba29 мая 2008 г.
- CVE-2023-3496649В плане
Samba: infinite loop in mdssvc rpc service for spotlight
ВысокаяCVSS 7,5Эксплойта нетEPSS 62 %samba · samba20 июл. 2023 г.
- CVE-2004-060049В плане
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an
КритическаяCVSS 10,0Proof of conceptEPSS 29 %samba · samba27 июл. 2004 г.
- CVE-2014-356048В плане
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code v
ВысокаяCVSS 7,9Эксплойта нетEPSS 56 %samba · samba6 авг. 2014 г.
- CVE-2003-019647В плане
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as disco
КритическаяCVSS 10,0Эксплойта нетEPSS 23 %samba · samba5 мая 2003 г.
- CVE-2007-601545В плане
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled
КритическаяCVSS 9,3Proof of conceptEPSS 27 %samba · samba13 дек. 2007 г.
- CVE-2004-088244В плане
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a
КритическаяCVSS 10,0Эксплойта нетEPSS 14 %samba · samba27 янв. 2005 г.
- CVE-2004-115444В плане
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 13 %samba · samba10 янв. 2005 г.
- CVE-2001-116244В плане
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overw
КритическаяCVSS 10,0Proof of conceptEPSS 12 %samba · samba23 июн. 2001 г.
- CVE-1999-018243В плане
Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.
КритическаяCVSS 10,0Proof of conceptEPSS 10 %samba · samba30 сент. 1997 г.
- CVE-2017-1474642В плане
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %samba · samba27 нояб. 2017 г.
- CVE-2013-412441В плане
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4
СредняяCVSS 5,0Готовый эксплойтEPSS 69 %samba · samba5 авг. 2013 г.
- CVE-2016-211841В плане
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DC
ВысокаяCVSS 7,5Proof of conceptEPSS 37 %samba · samba12 апр. 2016 г.