Vulnerabilities
Vulnerable Software
Samba:  >> Samba  >> 4.16.1  Security Vulnerabilities
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).
CVSS Score
9.8
EPSS Score
0.018
Published
2022-12-25
Netlogon RPC Elevation of Privilege Vulnerability
CVSS Score
8.1
EPSS Score
0.024
Published
2022-11-09
Windows Kerberos Elevation of Privilege Vulnerability
CVSS Score
7.2
EPSS Score
0.041
Published
2022-11-09
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
CVSS Score
8.1
EPSS Score
0.025
Published
2022-11-09
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
CVSS Score
7.5
EPSS Score
0.015
Published
2022-09-01
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
CVSS Score
5.5
EPSS Score
0.005
Published
2022-09-01
A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).
CVSS Score
4.3
EPSS Score
0.012
Published
2022-08-25
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
CVSS Score
8.8
EPSS Score
0.011
Published
2022-08-25
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.
CVSS Score
8.1
EPSS Score
0.011
Published
2022-08-25
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.
CVSS Score
5.4
EPSS Score
0.012
Published
2022-08-25


Contact Us

Shodan ® - All rights reserved