Skip to main content

Vendor archive

samba CVEs

Beta · best-effort

245 CVEs tagged to vendor samba29 Critical, 75 High, 120 Medium, 21 Low, 0 Unrated.

CVE-2004-0082

Published Mar 3, 2004

The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0028

Published Feb 3, 2004

jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1332

Published Dec 31, 2003

Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerab…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0085

Published Mar 31, 2003

Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0086

Published Mar 31, 2003

The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2196

Published Dec 31, 2002

Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1318

Published Dec 11, 2002

Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the ove…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-0080

Published Mar 15, 2002

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then r…

CVSS 2.1 · Low
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0406

Published Jul 2, 2001

Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput com…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1162

Published Jun 23, 2001

Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIO…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0935

Published Dec 19, 2000

Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0936

Published Dec 19, 2000

Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0937

Published Dec 19, 2000

Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0938

Published Dec 19, 2000

Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0939

Published Dec 19, 2000

Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and for…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0812

Published Jul 12, 2000

Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-1999-0810

Published Jul 21, 1999

Denial of service in Samba NETBIOS name service daemon (nmbd).

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-1999-0811

Published Jul 21, 1999

Buffer overflow in Samba smbd program via a malformed message command.

CVSS 5.0 · Medium
Buzz score
4.1
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 226-245 of 245 CVEsPage 10 of 10